Back to MD Exchange
    Automation Workflowssecurityowaspauditpentesting

    Web App Security Audit Checklist

    OWASP Top 10:2021 checklist plus API security, dependency scanning, CSP headers, and rate limiting.

    K
    katewilliams|March 4, 2026|Updated Oct 8
    414 downloads45 stars

    Uploaded markdown content, not a verification of tool compatibility or results. Review the raw text, commands, and permissions before using it. Stars require an account.


    name: security-audit


    Security Audit Checklist

    OWASP Top 10:2021

    This section follows the 2021 edition. For the newer edition, consult the [OWASP Top 10:2025](https://owasp.org/Top10/2025/).

    • [ ] A01: Broken Access Control
    • [ ] A02: Cryptographic Failures
    • [ ] A03: Injection (SQL, NoSQL, Command)
    • [ ] A04: Insecure Design
    • [ ] A05: Security Misconfiguration
    • [ ] A06: Vulnerable Components
    • [ ] A07: Auth Failures
    • [ ] A08: Data Integrity
    • [ ] A09: Logging Failures
    • [ ] A10: SSRF

    API

    • [ ] Auth on all endpoints
    • [ ] Rate limiting
    • [ ] Input validation

    Headers

    • [ ] CSP, X-Frame-Options, HSTS