
Web Security Self-Audit Kit (OWASP)
A lightweight, defense-focused audit of your own/authorized website or web app, driven by the OWASP Top 10. Non-destructively checks security headers, cookie attributes, XSS/SQLi exposure, dependency CVEs, and WordPress/Next.js-specific points. Each finding comes with a severity and an immediately actionable fix (config and code examples), output as a concise report. For full engagements (RoE, formal report), use the Pentest Engagement Kit. Authorized assets only.
#الهندسة
التقييم
مطلوب المزيد من التقييمات
المبيعات
0
كيفية الاستخدام
تنزيل
Web Security Self-Audit Kit (OWASP)
A quick "is my site safe?" check for your own site — defense and improvement, not attack. Findings come with fixes you can apply right away.
Who it's for
- Owners unsure where to start on website security
- Anyone wanting to verify headers/cookies and close common holes
What it does
- OWASP Top 10 review (access control, crypto, injection, misconfig, old deps, auth, SSRF)
- High-impact fixes: CSP/HSTS headers, cookie attributes, HTTPS, error exposure, CVE updates
- CMS-specific: WordPress (plugins, wp-admin, user enumeration), Next.js/SPA (API authz, env exposure, CORS)
- Concise report: severity, location, fix steps, checklist
Bundled
- references/web_checks.md — non-destructive review checklist
- references/audit_report_template.md — audit report template
Note
Authorized assets only. For full engagements/formal reports, use the Pentest Engagement Kit.


