Content Security Policy, Your Future Best Friend (sma) | | 118 |
csp, link-lists |
A Refined Content Security Policy (web) | | 117 |
html, csp, webkit, safari, apple, browsers |
The Performance Benefits of “rel=noopener” (jaf) | | 116 |
html, links, performance |
Web Platform Security Boundaries (ann) | | 115 |
web-platform |
Subresource Integrity (dev+/w3c) | | 114 |
hashing, html, standards |
W3C Looks to Secure the Web (sdt) | | 113 |
w3c, authentication |
Distribution Packages Considered Insecure | | 112 |
dependencies, unix-like |
The Current State of Web Security (An Interview With Anselm Hannemann) (hel+/css) | | 111 |
interviews, http, ssl, tls, encryption, cloudflare |
Eliminating Known Vulnerabilities With Snyk (sma) | | 110 |
vulnerabilities, tooling |
10 Web Predictions for 2016 (cra) | | 109 |
web, outlooks, site-generators, browsers, css, mobile, performance, webassembly, seo |
HSTS and “Let’s Encrypt” (tka) | | 108 |
http, http-headers, ssl |
An in-Depth Look at CORS | | 107 |
cors, javascript, php |
Why Passwordless Authentication Works (cra) | | 106 |
authentication, passwords |
A Simple Developer Error Is Exposing Private Information on Thousands of Websites (owe) | | 105 |
version-control, git, mistakes, vulnerabilities |
More Tips to Further Secure WordPress (eli) | | 104 |
wordpress, tips-and-tricks, plugins |
Improving Web Security With the Content Security Policy | | 103 |
csp, http |
Deprecating HTTP (yoa) | | 102 |
http, protocols |
Mozilla Wants to Deprecate Non-Secure HTTP, Will Make Proposals to W3C “Soon” (epr/ven) | | 101 |
mozilla, http |
Want Fancy Firefox Features? Secure Your Website (sts/cne) | | 100 |
firefox, mozilla, browsers, http |
WordPress Front End Security: CSRF and Nonces (css) | | 99 |
wordpress, csrf |
Introduction to WordPress Front End Security: Escaping the Things (css) | | 98 |
introductions, wordpress, escaping |
What Are the Security Risks of HTML5 Apps? | | 97 |
web-apps, sanitization |
Moving to HTTPS on WordPress (chr/css) | | 96 |
wordpress, http |
Same-Origin Policy (ann) | | 95 |
cors, web-platform |
Securing the Web (w3c) | | 94 |
web-platform |
It’s Time to Encrypt the Entire Internet (kli/wir) | | 93 |
web, http, ssl, encryption |
Cross-Origin Resource Sharing (ann/w3c) | | 92 |
cors, standards |
Despite Automatic Updates, Old Browsers Are Still a Problem (edb/zdn) | | 91 |
browsers, web-platform, chrome, google, firefox, mozilla, internet-explorer, microsoft, safari, apple |
Cross-Origin Resource Sharing on Track to Become a W3C Recommendation (sdt) | | 90 |
w3c, cors, standards |
Bid to Kill CAPTCHA Security Test Gains Momentum | | 89 |
captcha, accessibility |
We Should All Have Something to Hide | | 88 |
privacy |
Mobile Website Security | | 87 |
mobile, hosting, policies |
WordPress Security Tips | | 86 |
wordpress, tips-and-tricks |
Brad Hill: “HTML5 Security Realities” (chr/css) | | 85 |
slides, xss, html |
Bulletproof Your Drupal Website | | 84 |
drupal |
Top 10 PHP Security Vulnerabilities | | 83 |
php, vulnerabilities |
A Front End Engineer’s Manifesto (zac) | | 82 |
websites, manifestos, user-experience, progressive-enhancement, simplicity, foss, accessibility, community, learning |
A JavaScript Security Flaw | | 81 |
javascript |
The Secure Programmer’s Pledge | | 80 |
manifestos |
An Introduction to Content Security Policy (mik/dev) | | 79 |
introductions, csp |
Cross-Site Scripting Attacks (XSS) | | 78 |
xss, examples |
How to Secure Your WordPress Website (sma) | | 77 |
how-tos, wordpress, link-lists |
Using CORS (dev) | | 76 |
cors |
XML Encryption Flaw Leaves Web Services Vulnerable (eur) | | 75 |
web-services, xml, encryption |
Some Notes on the Recent XML Encryption Attack (w3c) | | 74 |
xml, encryption |
HTTPS Is More Secure, So Why Isn’t the Web Using It? (ars) | | 73 |
http, protocols, web |
Web Cryptography: Salted Hash and Other Tasty Dishes (ali) | | 72 |
cryptography |
What Are the JSON Security Concerns in Web Development? (sim) | | 71 |
json |
What Is Cross Site Scripting or XSS? (chr/css) | | 70 |
xss, javascript, concepts |
Web Developers Accountable for HTML 5 Security | | 69 |
html |
HTML5 Raises New Security Issues | | 68 |
html, browsers |
10 Useful WordPress Security Tweaks (sma) | | 67 |
wordpress |
Web Security: Are You Part of the Problem? (cod/sma) | | 66 |
vulnerabilities, php, javascript |
The Internet Is Closing to Innovation (zit/new) | | 65 |
web |
You Could Be Getting Clickjacked (tec) | | 64 |
vulnerabilities, frames, w3c |
Dumb Security Tips: Think Before You Follow Online Guides (tan) | | 63 |
tips-and-tricks |
Internet Explorer 8 Promises Better Standards Compliance… and a Whole Lot More (est/cio) | | 62 |
internet-explorer, microsoft, browsers, standards |
JavaScript Security Experiments (mar) | | 61 |
javascript, experiments |
DOM vs. Web (mno) | | 60 |
http, dom |
Top 7 PHP Security Blunders | | 59 |
php, databases, sql |
Validate Your Input! | | 58 |
validation |
JavaScript Security | | 57 |
javascript |
File Upload Security (lac) | | 56 |
html, file-handling |
Spot the Security Hole | | 55 |
php |
JavaScript and Security (sim) | | 54 |
javascript |
Handling Content From Strangers | | 53 |
content |
Web Services Security Gets Serious | | 52 |
web-services |
Getting Started With XML Security | | 51 |
introductions, xml |
Sorting Out the Web Services Security Landscape | | 50 |
web-services, ssl, w3c |
SSL Checker (EXPERTE.com) | | 49 |
tools, analysis, ssl |
ASCII to Unicode Encoder and Decoder | | 48 |
tools, exploration, conversion, unicode, encoding |
security.txt Generator | | 47 |
tools, exploration, content |
WebRTC and IP Address Leak Checker | | 46 |
tools, exploration, network, webrtc, ip, protocols |
Website Headers Analyzer (Dries Buytaert) (dri) | | 45 |
tools, analysis, http, http-headers |
User Identity Generator | | 44 |
tools, exploration, placeholders, randomness |
Subresource Integrity Hash Generator (moz) | | 43 |
tools, exploration, hashing |
SSL Client Checker | | 42 |
tools, exploration, ssl |
SPF Record Generator | | 41 |
tools, exploration, dns, domains |
SHA-512 Hash Generator | | 40 |
tools, exploration, hashing |
Security Leak Victim Checker | | 39 |
tools, exploration |
Password Security Checker | | 38 |
tools, exploration, passwords |
Password Security Checker and Generator | | 37 |
tools, exploration, passwords |
Password Generator (Gibson Research Corporation) | | 36 |
tools, exploration, passwords |
Password Generator (Frontend Dogma) (fro) | | 35 |
tools, exploration, frontend-dogma, passwords |
Password Generator (Arantius.com) | | 34 |
tools, exploration, passwords |
MD5 Hash Generator | | 33 |
tools, exploration, hashing |
HMAC Checker | | 32 |
tools, exploration |
Hash Generator | | 31 |
tools, exploration, hashing |
Executable File Analyzer | | 30 |
tools, exploration |
Device Vulnerability Checker | | 29 |
tools, exploration, vulnerabilities |
CSR Decoder | | 28 |
tools, exploration |
“chmod” Calculator | | 27 |
tools, exploration, permissions |
Browser Fingerprint Checker | | 26 |
tools, exploration, browsers |
Blowfish Hash Generator | | 25 |
tools, exploration, hashing |
AES Encrypter and Decrypter | | 24 |
tools, exploration, encryption |
Website Security Checker (Norton) | | 23 |
tools, analysis |
Website Security Checker (Google) | | 22 |
tools, analysis |
Website Scam Checker | | 21 |
tools, analysis |
Website Privacy Checker (dat) | | 20 |
tools, analysis, privacy |
Website Headers Analyzer (Security Headers) | | 19 |
tools, analysis, http, http-headers |
Website Headers Analyzer (Mozilla) (moz) | | 18 |
tools, analysis, http, http-headers |
Website Certificate Fingerprint Checker | | 17 |
tools, analysis |
Virus Scanner | | 16 |
tools, analysis |
SSL Checker (SSL Shopper) | | 15 |
tools, analysis, ssl |
SSL Checker (Qualys) | | 14 |
tools, analysis, ssl |
SPF Record Checker | | 13 |
tools, analysis, dns, domains |
Site and Origin Comparer | | 12 |
tools, analysis, comparisons |
Malware and Security Scanner | | 11 |
tools, analysis |
Email Blacklist Checker | | 10 |
tools, analysis, email |
Domain or IP Spam Checker | | 9 |
tools, analysis, domains |
DNSSEC Checker | | 8 |
tools, analysis, dns |
Cross-Site WebSocket Hijacking Tester | | 7 |
tools, analysis |
Cookie Use Checker | | 6 |
tools, analysis, cookies |
Content Security Policy Validator (Google) | | 5 |
tools, analysis, csp, conformance |
Content Security Policy Validator (CSP Validator) | | 4 |
tools, analysis, csp, conformance |
Abuse Contact Lookup | | 3 |
tools, analysis, policies |
Server Port Scanner | | 2 |
tools, analysis, network, servers |
Website Experience Analyzer | | 1 |
tools, analysis, performance, user-experience |