Back to Checklists
OWASP ASVS 5.0.0OWASP Top 10:2025

Web Application Security

Core application security controls covering authentication, authorization, session handling, input validation, and API routes.

Support SafeToShip

Audit Progress: 0 of 10 verified

Check off items as you verify them in your codebase. Progress is saved locally.

Showing 10 checks
AuthenticationCritical

Passwords are securely hashed server-side

Verify that passwords are never stored in plaintext or reversibly encrypted, and use a strong salt-per-user hashing algorithm like Argon2id or bcrypt.

AuthenticationHigh

Login & sensitive routes have rate limiting

Protect login, password reset, and sensitive endpoints against brute-force attacks and credential stuffing.

AuthenticationHigh

MFA / 2FA verification cannot be bypassed

Ensure multi-factor authentication controls are strictly enforced server-side and cannot be skipped by manipulating client requests.

Authorization & Access ControlCritical

Server-side authorization on all direct object access (IDOR)

Validate that every endpoint accepting a record ID checks user ownership or organisation membership before returning or modifying data.

Session ManagementHigh

Session cookies use HttpOnly, Secure, and SameSite flags

Protect session identifiers from cross-site scripting (XSS) and cross-site request forgery (CSRF) using strict cookie security attributes.

Input Validation & InjectionCritical

Database queries are parameterized against SQL/NoSQL injection

Ensure user input is never concatenated directly into SQL queries or dynamic database command strings.

Output Encoding & XSSHigh

User-generated HTML/Markdown is sanitized against XSS

Prevent Reflected and Stored Cross-Site Scripting by escaping or sanitizing any user input rendered in the browser.

Secrets & CredentialsCritical

No production API keys or secrets in frontend bundles

Verify that service role keys, database connection strings, and private API keys are not exposed in public environment variables or client builds.

File Uploads & StorageHigh

File uploads validate size, extension, and MIME type

Restrict uploaded files to safe types, isolate storage outside web roots, and enforce file size constraints.

SSR / Next.js SecurityCritical

Server Actions and Route Handlers verify authentication & authorization

Ensure Next.js Server Actions and API Route Handlers independently verify the user's session before performing state changes.