Security Guide for Developers
-
Updated
Aug 30, 2025
Security Guide for Developers
Checklist of the most important security countermeasures when designing, creating, testing your web/mobile application
A comprehensive security checklist for vibe coders
This is CheatSheet which I used on PJPT exam to fully compromise Domain Controller by doing internal network penentration testing.
A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth flows, and remote server risks. Maintained by Appsecco and licensed for remixing.
The SaaS CTO Security Checklist Redux, The DevOps Security Checklist, and The Personal Infosec & Security Checklist
☑️ A security checklist for anyone who's developing and deploying APIs
Security cheat sheets for different language and platforms
The ultimate OWASP MCP Top 10 security checklist and pentesting framework for Model Context Protocol (MCP), AI agents, and LLM-powered systems.
Checklists e prompts de cibersegurança para projetos de vibe coding em PT
Ref: Personal checklists for running Node in production
📓 Guia de segurança para DevComputeiros
Advanced GraphQL penetration testing checklist — covering introspection, auth bypass, injection, DoS, SSRF, subscription attacks & more. Built for security engineers & bug bounty hunters. 🔥
Local-first governance layer for safer AI-assisted development: routes, scorecards, trust checks, evidence bundles and team adoption playbooks.
BugOps: A professional-grade, interactive bug bounty methodology and security checklist for modern researchers. Built with React & TypeScript. 🚀
A practical pre-launch security checklist for taking real money through Stripe (Node/React). The checks a reviewer actually runs before go-live.
Security checklist and audit tools for MCP (Model Context Protocol) server deployments
Field-ready internal network penetration testing checklist aligned with PTES, NIST SP 800-115, OWASP, CIS Benchmarks and MITRE ATT&CK covering pre-engagement through reporting, AD & non-AD environments, and manual verification commands for 24+ services.
A stack-agnostic web application penetration testing checklist based on OWASP WSTG, ASVS, PTES & NIST.
🛡️ Comprehensive implementation checklist and toolkit for ACSC Essential Eight Maturity Model (ML1-ML3)
Add a description, image, and links to the security-checklist topic page so that developers can more easily learn about it.
To associate your repository with the security-checklist topic, visit your repo's landing page and select "manage topics."