Loslegen
Web Security Self-Audit Kit (OWASP)

Web Security Self-Audit Kit (OWASP)

A lightweight, defense-focused audit of your own/authorized website or web app, driven by the OWASP Top 10. Non-destructively checks security headers, cookie attributes, XSS/SQLi exposure, dependency CVEs, and WordPress/Next.js-specific points. Each finding comes with a severity and an immediately actionable fix (config and code examples), output as a concise report. For full engagements (RoE, formal report), use the Pentest Engagement Kit. Authorized assets only.
#Ingenieurwesen
Rating
Weitere Bewertungen erforderlich
Sold
0
How to use
Herunterladen

Web Security Self-Audit Kit (OWASP)

A quick "is my site safe?" check for your own site — defense and improvement, not attack. Findings come with fixes you can apply right away.

Who it's for

  • Owners unsure where to start on website security
  • Anyone wanting to verify headers/cookies and close common holes

What it does

  • OWASP Top 10 review (access control, crypto, injection, misconfig, old deps, auth, SSRF)
  • High-impact fixes: CSP/HSTS headers, cookie attributes, HTTPS, error exposure, CVE updates
  • CMS-specific: WordPress (plugins, wp-admin, user enumeration), Next.js/SPA (API authz, env exposure, CORS)
  • Concise report: severity, location, fix steps, checklist

Bundled

  • references/web_checks.md — non-destructive review checklist
  • references/audit_report_template.md — audit report template

Note

Authorized assets only. For full engagements/formal reports, use the Pentest Engagement Kit.