✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Web Application Security Checklist 2026: 20 Points to Check

Web Application Security Checklist 2026: 20 Points to Check

Many web applications contain vulnerabilities that a basic check would have already caught. This checklist helps developers, security engineers and product owners quickly work through the most critical security points. It’s not a replacement for a professional pentest, but a good starting point for self-assessment.

Authentication & sessions

  • Multi-factor authentication (MFA) — Is MFA enabled for all admin accounts? And for end users with access to sensitive data?
  • Password policy — Are weak passwords rejected? Are leaked passwords checked (via Have I Been Pwned or similar)?
  • Session expiry — Do sessions expire after inactivity? Are session tokens invalidated after logout?
  • Account lockout — Is there a lockout after multiple failed login attempts?
  • Secure password storage — Are passwords hashed with bcrypt, Argon2 or scrypt — never MD5 or SHA-1?

Authorization

  • Broken Access Control — Can a user access other users’ objects by modifying the ID in the URL (IDOR)?
  • Privilege escalation — Can a regular user reach admin functions through direct URL calls?
  • API authorization — Are all API endpoints checked for authorization, including direct calls without the frontend?

Input validation & injection

  • SQL injection — Are all database queries parameterised or executed via an ORM?
  • Cross-Site Scripting (XSS) — Is user input escaped on display? Is Content Security Policy (CSP) correctly configured?
  • Command injection — Are system calls with user input avoided, or safely sandboxed?
  • File upload security — Are uploaded files validated for type and content? Are they stored outside the web root?

Configuration & infrastructure

  • HTTPS everywhere — Is all communication encrypted via HTTPS? Is HSTS correctly configured?
  • Security headers — Are X-Frame-Options, X-Content-Type-Options, Referrer-Policy and CSP present and correct?
  • Software updates — Are all frameworks, libraries and dependencies up to date? Do you use a dependency scanner (e.g. Snyk or Dependabot)?
  • Error messages — Are stack traces and technical error details hidden from end users?
  • Debug mode — Is debug mode disabled in production?

Logging & monitoring

  • Login attempts logged — Are failed login attempts, password resets and MFA changes logged?
  • Log integrity — Are logs stored somewhere the application itself can’t delete them?
  • Alerting — Are there alerts for suspicious patterns (brute force, unusual times, high-volume API calls)?

What if you find gaps here?

Prioritise based on impact and exploitability. Critical points (SQL injection, IDOR, no MFA on admin) come first. Consider a professional web application pentest for a full, manual assessment — including vulnerabilities a checklist won’t find.

FAQ

Is this checklist complete?

No — this is a starting point for self-assessment, based on the OWASP Top 10. A professional pentest goes further: logic flaws, business-layer vulnerabilities and complex attack chains can’t be found without manual testing.

How often should I test my web application?

At least annually, and after every significant change. With active development, integrating security into the CI/CD pipeline (DevSecOps) is the most effective approach.

Read more about web application pentests  ·  Request a quote

Scroll to Top