Skip to main content
WebsiteintermediateFree

web.dev/security

Unknown

web.dev/security is Google's resource hub with tutorials, guides, and best-practice references for securing web applications, from HTTPS and security headers to authentication, permissions, and common vulnerabilities.

Visit resource

More resources on Web Security

WebsiteFree

OWASP Foundation

Nonprofit foundation publishing open web application security standards and guides, including the OWASP Top Ten, the Application Security Verification Standard, the Web Security Testing Guide and the Cheat Sheet Series, used to identify, test for and prevent common web vulnerabilities.

WebsiteFree

Mozilla Observatory

Mozilla's free scanner that grades a website's HTTP security configuration. Checks headers such as Content-Security-Policy, Strict-Transport-Security, and X-Frame-Options plus cookie and redirect settings, explaining each failed test so developers can harden their own sites.

CourseFree

OWASP Secure Coding Practices

Learn essential web-security practices with OWASP's Secure Coding course. Build robust, secure applications following industry standards.

BookPaid

Web Security for Developers

A No Starch Press guide to the most common web application vulnerabilities, written for developers rather than security specialists. Explains injection, cross-site scripting, CSRF, broken authentication, and session hijacking with concrete code-level defenses, so readers can build and review safer web applications.

CourseFree

Web Application Security

This course covers essential web security concepts and secure coding practices. You’ll learn to identify common vulnerabilities, implement protection techniques, and leverage Microsoft Copilot to detect and fix security issues in web applications. By the end of this program, you will be able to… Define common web application vulnerabilities and principles of secure coding. Explain the concepts and impacts of SQL injection, XSS, CSRF, input validation techniques, and best practices for authentication and authorization. Describe the importance of output encoding, sanitization, secure data storage, and transmission. Enhance the security of web applications with Microsoft Copilot to detect vulnerabilities, fix issues, and implement secure coding practices.

See all Web Security resources →