SQL injection, leaked secrets, default passwords - how many of the basics are you actually getting right?
Includes a personalized analysis written by Seth based on 20+ years of engineering and startup experience.
10 questions · ~2 minutes
Question 1 of 10Authentication & Sessions
How do you store passwords in your database?
Question 2 of 10Input & Data Handling
How do you build database queries?
Question 3 of 10Secrets & Credentials
Where are your API keys and database passwords?
Question 4 of 10Input & Data Handling
How do you handle user-uploaded files?
Question 5 of 10Access Control & Permissions
What does your database user have permission to do?
Question 6 of 10Authentication & Sessions
How do you handle session management?
Question 7 of 10Input & Data Handling
How do you handle output encoding (preventing XSS)?
Question 8 of 10Secrets & Credentials
How do you handle SSH keys and deployment credentials?
Question 9 of 10Access Control & Permissions
What happens when an employee or contractor leaves?
Question 10 of 10Authentication & Sessions
Have you ever run a security scan or audit on your app?
One last step.
Enter your email to unlock your score, category breakdown, and a personalized analysis with article recommendations based on 20+ years of engineering and startup experience.
Thinking...
This takes a few seconds while we generate your personalized analysis.