Secure development basics: the OWASP Top 10 in practice
For developers, automation engineers and IT staff who write or review scripts, internal web tools or APIs. You should be able to read simple Python or JavaScript; you don't need security experience. Uses the OWASP Top 10:2025 categories (with the 2021 numbering alongside, since many tools still use it) and turns the most common ones into things you can spot in code review: injection, broken access control, secrets and weak password storage, authentication flaws, misconfiguration, risky dependencies and unsafe error handling.
- Level
- Intermediate
- Length
- About 85 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify injection flaws in code that builds SQL or shell commands from user input, and choose a parameterized fix
- Identify missing authorization checks where a user-supplied identifier selects a record
- Choose acceptable password storage and secret handling, and write login and error messages that don't leak details while logging them server-side
- Identify security misconfiguration and risky dependencies in configuration files and dependency scan output
- Match code review findings to their OWASP Top 10:2025 category
Course outline
- 1.The Top 10 as a code reviewer's mapLesson · 10 min
- 2.Injection: SQL and shell commands built from user inputLesson · 12 min
- 3.Broken access control: missing authorization checks on recordsLesson · 8 min
- 4.Secrets, password storage, login and error messagesLesson · 18 min
- 5.Security misconfiguration, risky dependencies and a review checklistLesson · 14 min
- 6.Secure development basics: the OWASP Top 10 in practice: knowledge checkKnowledge check · 14 questions
- 7.Secure development basics: the OWASP Top 10 in practice: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- OWASP Top 10:2025 (category list)
- OWASP Top 10:2021 (category list)
- OWASP Top 10:2025 A01 Broken Access Control
- OWASP Top 10:2025 A02 Security Misconfiguration
- OWASP Top 10:2025 A03 Software Supply Chain Failures
- OWASP Top 10:2025 A04 Cryptographic Failures
- OWASP Top 10:2025 A05 Injection
- OWASP Top 10:2025 A07 Authentication Failures
- OWASP Top 10:2025 A10 Mishandling of Exceptional Conditions
- OWASP Cheat Sheet Series: SQL Injection Prevention Cheat Sheet
- OWASP Cheat Sheet Series: Secrets Management Cheat Sheet
- OWASP Cheat Sheet Series: Error Handling Cheat Sheet
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.