What you will find
Long-form guides and short lists on the bugs that still show up in production: a bind that never ran, a cookie without a Host prefix, a lockfile that installed hostile code.
About
SecureCoding is a free library of notes for people who ship web software and have to lock it down. Each guide names a control you can put in the product this week, with a date and a link to the source. We are not a scanner company and we do not sell a platform.
The site covers XSS, CSRF, injection, authentication, lockfiles, cloud setup, and language runtimes. When a CVE floor, an OWASP filename, or a runtime default changes, we update the page. Corrections go to Contact.
Long-form guides and short lists on the bugs that still show up in production: a bind that never ran, a cookie without a Host prefix, a lockfile that installed hostile code.
Engineers, reviewers, and security folks who need a named helper and a first-party citation, not a webinar pitch or a tool roll call.
Exploit walkthroughs, malware rebuilds, and unsigned product plugs. If a page cannot name the control, it does not ship.
The byline is the SecureCoding editorial team. The site is securecoding.com. Write contact@securecoding.com or use the contact form.
AboutContactTermsPrivacyCookies
No. This is an editorial site. We mention a tool only when its first-party docs are the control. We do not take a cut for listing one.
Yes, in your own app, at your own risk. The terms say the guides are not professional advice. Keep a short attribution if you quote more than a brief excerpt.
Use Contact. Name the URL and the line. We will check the first-party source and fix the page.