WeWeb Logo

Security happens in the backend

Web App Security Checklist

Anything that reaches the browser is visible to the user. These 16 tests tell you what actually got through.

0 of 16 passed

0%
01

AUTH & ACCESS

Test like a hacker.

🔐
02

DATA & SECRETS

Consider it public until you test it.

🗄️
03

INPUT & INTEGRATIONS

Never trust user input.

🧹
04

ABUSE PROTECTION

Never assume the user “won’t find out".

🚦
05

LOGGING & RETESTING

No app is 100% secure. Keep testing.

🔎
🤖

Hand this to your coding agent

Copies a ready-to-use prompt for Claude, ChatGPT or Cursor with all 16 tests, your unticked items marked FAILED and ticked items marked PASSED to verify.

🫵 Hiding a button, field or page in the frontend is UX. It is NOT security.

Full guide: How to make secure web apps →