Skip to content

The OWASP Web Security Testing Guide

A shared checklist for testing web applications, and how to use it without turning testing into box-ticking.

Editorial team 2 min read

The OWASP Web Security Testing Guide (WSTG) is the closest thing the industry has to a shared methodology for testing web applications. Its value is coverage: it stops a tester from spending three days on injection and never looking at session management.

How it is organised

Testing is grouped by area — information gathering, configuration, identity management, authentication, authorisation, session management, input validation, error handling, cryptography, business logic and client-side. Each area lists objectives and how to approach them.

Using it well

Work through the areas, but let the application decide the depth. A read-only marketing site deserves an hour on configuration; a multi-tenant billing system deserves days on authorisation and business logic.

The guide tells you what to look at, not what matters here. That judgement is the job.

Where findings actually come from

In practice most serious findings in modern applications cluster in three places: authorisation (one user reaching another's data), business logic (a legitimate sequence of requests producing an illegitimate outcome), and authentication flows (reset, enrolment, federation and session lifetime).

Framework defaults have largely removed the classic injection and output encoding issues from well-built applications; access control cannot be fixed by a framework default, because only the application knows who should see what.

More in Cyber security

All Cyber security guides →
Cyber security Guide · 2 min

What a Penetration Test Is, and Is Not

A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.

Cyber security 2 min read 25 May 2025

Cyber security Guide · 2 min

Rules of Engagement and Authorisation

What to agree before any testing starts: scope, timing, data handling, escalation and the single document that makes the work lawful.

Cyber security 2 min read 24 May 2025

Cyber security Guide · 2 min

Writing a Finding People Will Fix

Severity, evidence, reproduction, impact in business terms, and a fix the team can actually make.

Cyber security 2 min read 23 May 2025

Cyber security Guide · 2 min

Vulnerability Scanning Done Properly

Credentialed scans, asset coverage, tuning out noise, and why scan counts are a bad metric.

Cyber security 2 min read 22 May 2025