262+ in-depth guides on vulnerabilities, attack surfaces, secure coding, and compliance — free and open.
Explore our security guides organized by topic.
Comprehensive guides for different types of cyber attacks
Guides to secure cookies — the Secure, HttpOnly and SameSite flags and how to check them.
Reference guides to DNS record types — what each record does, the fields it contains, and how to …
Comprehensive security guides for popular web frameworks
Security guides for programming languages — learn to find and fix vulnerabilities in Python, PHP, Java, JavaScript, Go …
What is port X? Security guides for common network ports
Guides to SSL/TLS certificates — the chain of trust, invalid-certificate errors, renewal, and monitoring.
Reference guides to HTTP security headers — what each one does, its syntax, and how to check it.
Step-by-step tutorials on security scanning and testing
Comprehensive security vulnerability guides covering common web and network weaknesses — how each flaw works, how to detect …
Our latest security guides and analysis.
What the Secure cookie flag does, how it keeps cookies to HTTPS only, how it works with HSTS …
What the HttpOnly cookie flag does, how it hides cookies from JavaScript to stop session theft via XSS, …
What the SameSite cookie attribute does, the difference between Strict, Lax and None, how it defends against CSRF, …
Cookie security explained: the Secure, HttpOnly and SameSite flags that protect session cookies from theft and CSRF, plus …
What the Permissions-Policy header does, how it disables browser features like camera and geolocation to shrink attack surface, …
What the Referrer-Policy header does, its values (no-referrer, strict-origin-when-cross-origin, and more), how it prevents URL leaks, and how …
Scan your website for the vulnerabilities covered in these guides — free, no signup required.
Start Free Scan