Get listed

About

SecureCoding publishes application security guides

SecureCoding is a free library of notes for people who ship web software and have to lock it down. Each guide names a control you can put in the product this week, with a date and a link to the source. We are not a scanner company and we do not sell a platform.

The site covers XSS, CSRF, injection, authentication, lockfiles, cloud setup, and language runtimes. When a CVE floor, an OWASP filename, or a runtime default changes, we update the page. Corrections go to Contact.

What you will find

Long-form guides and short lists on the bugs that still show up in production: a bind that never ran, a cookie without a Host prefix, a lockfile that installed hostile code.

Who it is for

Engineers, reviewers, and security folks who need a named helper and a first-party citation, not a webinar pitch or a tool roll call.

What we skip

Exploit walkthroughs, malware rebuilds, and unsigned product plugs. If a page cannot name the control, it does not ship.

Who publishes this

The byline is the SecureCoding editorial team. The site is securecoding.com. Write contact@securecoding.com or use the contact form.

Start reading

Open the blog

Questions

Do you sell a product?

No. This is an editorial site. We mention a tool only when its first-party docs are the control. We do not take a cut for listing one.

Can I reuse a code sample?

Yes, in your own app, at your own risk. The terms say the guides are not professional advice. Keep a short attribution if you quote more than a brief excerpt.

How do I report a wrong date or a broken snippet?

Use Contact. Name the URL and the line. We will check the first-party source and fix the page.