Security is easiest when it is part of everyday development rather than a final audit. The checklist below covers the issues that appear again and again in web applications, closely following the categories popularised by the OWASP Top 10.
Input and output
- Validate input on the server against an allow-list of expected formats
- Use parameterised queries or an ORM — never build SQL from strings
- Encode output for its context (HTML, attribute, URL, JavaScript) to prevent XSS
- Set a Content Security Policy as a second line of defence
Authentication and sessions
- Hash passwords with a slow, salted algorithm such as bcrypt or Argon2
- Support multi-factor authentication
- Mark session cookies HttpOnly, Secure and SameSite
- Rate-limit login and password-reset endpoints
Authorisation
Check permissions on the server for every request, including API calls the UI “never makes”. Broken access control — users reaching data that is not theirs — is one of the most common serious flaws.
Secrets and configuration
- Never commit secrets; load them from environment variables or a secrets manager
- Use different credentials per environment
- Disable debug output and detailed errors in production
Dependencies
Keep dependencies updated, pin versions with a lockfile and run automated vulnerability scanning in CI.
Logging and monitoring
Log security-relevant events — failed logins, permission denials, admin actions — without logging passwords, tokens or personal data.
FAQ
Is a web application firewall enough?
A WAF helps block known attack patterns, but it cannot fix flaws in your application logic such as missing authorisation checks. Treat it as an additional layer, not a replacement.
How often should we review security?
Continuously in code review, with periodic deeper reviews or penetration tests before major releases or after significant architectural changes.
- AppSec
- OWASP
- Best Practices


