The list in plain English (2021 edition)
| Risk | What it means | Typical first fix |
|---|---|---|
| Broken access control | Users can reach data or actions they should not | Server-side checks on every request |
| Cryptographic failures | Sensitive data is not protected properly | HTTPS everywhere; encrypt sensitive data; strong password hashing |
| Injection | Untrusted input runs as code or queries | Parameterised queries; input validation |
| Insecure design | Security was not planned into the feature | Threat-model risky flows early |
| Security misconfiguration | Defaults, open storage or debug modes left on | Harden configs; remove unused features |
| Vulnerable and outdated components | Libraries with known flaws | Update dependencies; scan regularly |
| Identification and authentication failures | Weak login, session or password handling | Use proven auth providers and MFA |
| Software and data integrity failures | Unverified updates or pipelines | Lock dependencies; protect CI/CD |
| Security logging and monitoring failures | Attacks go unnoticed | Log key events and alert on anomalies |
| Server-side request forgery (SSRF) | The server fetches attacker-chosen URLs | Allow-list outbound requests |
Where AI-built apps usually fail
- Access control: the UI hides things but the API does not check
- Misconfiguration: open databases and exposed keys
- Outdated components: copied snippets with old libraries
- Missing logging: no way to see attacks
Founder’s 10-minute self-check
- Try opening another user’s record by changing an ID in the URL.
- Search your front-end code for API keys.
- Check that the database is not publicly readable.
- Confirm HTTPS and secure cookies.
- Look at dependency alerts in GitHub.
- Make sure admin pages require admin login.
Then book a proper test: see our penetration testing guide.
Get your app tested QA from $20/h
Tell us your app, platforms and release date. We scope the hours and quote.
Frequently asked questions
Is the OWASP Top 10 a standard?
It is an awareness document widely used as a baseline, not a legal standard.
Will fixing the Top 10 make me secure?
It covers the most common risks, but not everything; pair it with testing and monitoring.
Do you test against OWASP?
Yes. Our security testing is OWASP-aligned.
Get a free quote in 24 hours
Tell us what you need. We reply with scope, timeline and a fixed price.