Generate your Content Security Policy
The 7 Main XSS Cases Everyone Should Know - Brute XSS
Comparing XSStrike with other XSS Scanners
terrylinooo/shieldon: Web Application Firewall (WAF) for PHP.
Testing for XSS (Like a KNOXSS) - Brute XSS
The Absurdly Underestimated Dangers of CSV Injection
Set Access-Control-Allow-Origin (CORS) headers in Apache vhost or htaccess
Migrating to password_verify
voku/anti-xss
I’m harvesting credit card numbers and passwords from your site. Here’s how.
Haunted By Data
Be Watchful: PHP And WordPress Functions That Can Make Your Site Insecure