All articles
Cybersecurity

A Secure Coding Checklist for Web Applications

Most web vulnerabilities come from a small set of recurring mistakes. A practical checklist developers can apply on every pull request.

Nexeon Team1 min read

Security is easiest when it is part of everyday development rather than a final audit. The checklist below covers the issues that appear again and again in web applications, closely following the categories popularised by the OWASP Top 10.

Input and output

  • Validate input on the server against an allow-list of expected formats
  • Use parameterised queries or an ORM — never build SQL from strings
  • Encode output for its context (HTML, attribute, URL, JavaScript) to prevent XSS
  • Set a Content Security Policy as a second line of defence

Authentication and sessions

  • Hash passwords with a slow, salted algorithm such as bcrypt or Argon2
  • Support multi-factor authentication
  • Mark session cookies HttpOnly, Secure and SameSite
  • Rate-limit login and password-reset endpoints

Authorisation

Check permissions on the server for every request, including API calls the UI “never makes”. Broken access control — users reaching data that is not theirs — is one of the most common serious flaws.

Secrets and configuration

  • Never commit secrets; load them from environment variables or a secrets manager
  • Use different credentials per environment
  • Disable debug output and detailed errors in production

Dependencies

Keep dependencies updated, pin versions with a lockfile and run automated vulnerability scanning in CI.

Logging and monitoring

Log security-relevant events — failed logins, permission denials, admin actions — without logging passwords, tokens or personal data.

FAQ

Is a web application firewall enough?

A WAF helps block known attack patterns, but it cannot fix flaws in your application logic such as missing authorisation checks. Treat it as an additional layer, not a replacement.

How often should we review security?

Continuously in code review, with periodic deeper reviews or penetration tests before major releases or after significant architectural changes.

  • AppSec
  • OWASP
  • Best Practices
A Secure Coding Checklist for Web Applications | Your Site Name