Web Application Security Checklist 2026: 20 Points to Check
Many web applications contain vulnerabilities that a basic check would have already caught. This checklist helps developers, security engineers and product owners quickly work through the most critical security points. It’s not a replacement for a professional pentest, but a good starting point for self-assessment.
Authentication & sessions
- Multi-factor authentication (MFA) — Is MFA enabled for all admin accounts? And for end users with access to sensitive data?
- Password policy — Are weak passwords rejected? Are leaked passwords checked (via Have I Been Pwned or similar)?
- Session expiry — Do sessions expire after inactivity? Are session tokens invalidated after logout?
- Account lockout — Is there a lockout after multiple failed login attempts?
- Secure password storage — Are passwords hashed with bcrypt, Argon2 or scrypt — never MD5 or SHA-1?
Authorization
- Broken Access Control — Can a user access other users’ objects by modifying the ID in the URL (IDOR)?
- Privilege escalation — Can a regular user reach admin functions through direct URL calls?
- API authorization — Are all API endpoints checked for authorization, including direct calls without the frontend?
Input validation & injection
- SQL injection — Are all database queries parameterised or executed via an ORM?
- Cross-Site Scripting (XSS) — Is user input escaped on display? Is Content Security Policy (CSP) correctly configured?
- Command injection — Are system calls with user input avoided, or safely sandboxed?
- File upload security — Are uploaded files validated for type and content? Are they stored outside the web root?
Configuration & infrastructure
- HTTPS everywhere — Is all communication encrypted via HTTPS? Is HSTS correctly configured?
- Security headers — Are X-Frame-Options, X-Content-Type-Options, Referrer-Policy and CSP present and correct?
- Software updates — Are all frameworks, libraries and dependencies up to date? Do you use a dependency scanner (e.g. Snyk or Dependabot)?
- Error messages — Are stack traces and technical error details hidden from end users?
- Debug mode — Is debug mode disabled in production?
Logging & monitoring
- Login attempts logged — Are failed login attempts, password resets and MFA changes logged?
- Log integrity — Are logs stored somewhere the application itself can’t delete them?
- Alerting — Are there alerts for suspicious patterns (brute force, unusual times, high-volume API calls)?
What if you find gaps here?
Prioritise based on impact and exploitability. Critical points (SQL injection, IDOR, no MFA on admin) come first. Consider a professional web application pentest for a full, manual assessment — including vulnerabilities a checklist won’t find.
FAQ
Is this checklist complete?
No — this is a starting point for self-assessment, based on the OWASP Top 10. A professional pentest goes further: logic flaws, business-layer vulnerabilities and complex attack chains can’t be found without manual testing.
How often should I test my web application?
At least annually, and after every significant change. With active development, integrating security into the CI/CD pipeline (DevSecOps) is the most effective approach.
