Security Readiness
Review website security controls relevant to OWASP guidance
OWASP provides widely recognized guidance for understanding and reducing web application security risks.
WebInspect examines externally visible website security controls and configuration issues, highlighting findings that may be relevant to OWASP security guidance and the OWASP Top 10.
This provides website owners, developers and IT professionals with a practical way to identify security configuration issues that may deserve further investigation.
The Open Worldwide Application Security Project (OWASP) is a nonprofit organization focused on improving software security.
One of its best-known projects is the OWASP Top 10, which identifies major categories of security risks affecting web applications.
OWASP guidance is widely used by developers, security professionals and organizations when designing, developing and reviewing web applications.
Many web application vulnerabilities can only be identified through deeper application testing, authenticated assessments or source-code review.
However, several externally visible security controls and configuration issues can still provide useful indicators.
WebInspect examines applicable areas including:
Secure communication is fundamental to protecting information transmitted between visitors and web applications.
WebInspect checks HTTPS availability, SSL certificate information and supported TLS protocol versions.
Weak or outdated transport security can be particularly relevant when considering cryptographic security risks.
Learn about SSL/TLS Security Checks
Security headers allow websites to establish browser-side security policies.
WebInspect examines controls including Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy.
Missing or weak security controls may be relevant when reviewing the overall security configuration of a web application.
Learn about Security Header Checks
Content Security Policy can restrict the locations from which browsers are permitted to load scripts, styles and other resources.
A well-designed CSP can provide an additional layer of protection against certain content-injection and cross-site scripting scenarios.
WebInspect checks whether CSP is present and can highlight configuration that may deserve further review.
Cross-Origin Resource Sharing (CORS) determines how a website permits resources to be accessed from other origins.
Overly permissive or inappropriate CORS configuration can create security concerns, particularly when sensitive application functionality or data is involved.
WebInspect examines externally observable CORS behavior as part of its browser security checks.
Cookies are frequently used for sessions, preferences and authentication-related functionality.
Where cookies are observed, WebInspect can examine security attributes such as Secure, HttpOnly and SameSite.
The appropriate configuration depends on how each cookie is used, so cookie findings may require additional manual review.
Unnecessary information exposed by a website can provide attackers with useful details about the environment.
WebInspect includes checks for certain publicly accessible files, configuration indicators, verbose information and other externally observable conditions that may indicate security misconfiguration or unnecessary exposure.
Where appropriate, WebInspect reports can identify findings that are relevant to OWASP security categories.
For example, issues involving transport encryption may relate to cryptographic security risks, while missing browser protections, unnecessarily exposed information or insecure configuration may be relevant to security misconfiguration.
These references provide context around a finding. They do not mean that WebInspect has tested every vulnerability represented by an OWASP Top 10 category.
No.
This is an important distinction.
WebInspect performs an unauthenticated external inspection of publicly observable website and domain security controls.
Some OWASP risks require considerably deeper testing.
For example, determining whether an application has broken access controls, injection vulnerabilities, insecure authentication logic or authorization flaws may require authenticated testing, application interaction, source-code analysis or manual penetration testing.
WebInspect does not claim that a website is secure against every OWASP Top 10 risk simply because its external security checks pass.
OWASP is not a regulatory compliance standard or certification scheme.
Therefore, WebInspect does not provide an "OWASP certification" or declare a website "OWASP compliant."
Instead, WebInspect references applicable OWASP guidance to help explain the security significance of particular findings and to provide useful context for remediation.
An external security inspection can provide a useful first step in identifying common security configuration problems.
It can help uncover issues such as:
Finding these issues does not replace a comprehensive security assessment, but it can help organizations identify areas worth investigating and improving.
OWASP and PCI DSS serve different purposes, but some technical security practices can be relevant to both.
For example, secure transport, appropriate configuration and protection of web applications are important considerations across many security frameworks.
WebInspect therefore provides both OWASP relevance and PCI DSS readiness context where applicable, while keeping the two frameworks clearly distinguished.
Learn about PCI DSS Security Readiness
WebInspect examines multiple areas of your public website and domain, including HTTPS, TLS, security headers, email authentication and other externally visible security controls.
Explore our security checks to understand what each test looks for and why it matters.
Explore WebInspect Security Checks
Run a WebInspect inspection to identify externally visible security findings and see where applicable results relate to OWASP security guidance.
No account is required to start your free security snapshot.
Run a Free Website Security Scan