OWASP Top 10:2025, explained for website owners

Ten doors hackers try first. Which one did you leave open?

Security experts publish the list. Attackers read it too. Here it is in plain English, with a 30-point self-check so you can find out where your website stands before somebody else does.

The list was written for developers. The damage lands on you.

Every few years the OWASP Foundation, a nonprofit, studies test data from a huge number of real applications and publishes the ten kinds of weakness that keep getting websites broken into.

Developers know it by heart. Security testers work through it line by line. And the automated tools attackers run against millions of sites every night are built around exactly the same ten categories.

The one person who almost never reads it is the person who owns the website.

That's a problem, because you're the one who pays when it goes wrong.

You answer the angry customers. You send the breach notices. You watch Google put a red warning on the site you spent years building.

So we rewrote the list for you. No code. No acronyms you have to look up. For each of the ten, you'll get what it means, what it looks like on a site like yours, and three yes-or-no questions. Tick the ones that are true today.

Fifteen minutes from now you'll know which doors are locked, and which ones you only hoped were.

The OWASP Top 10 self-check

A01 Broken Access Control

Your site lets someone see or do something they shouldn't. It's number one for a reason: almost every site we test has some version of it.

On a real site: a customer opens their invoice at /invoice?id=1042, changes it to 1041, and reads a stranger's name, address and order. Nothing was hacked. The site simply never checked whose invoice it was.

In our audit: Standard area 03 (access) and 05 (application security). We log in as two different customers and try to cross the line.

A02 Security Misconfiguration

The software is fine. The settings aren't. Default passwords, debug pages left switched on, folders anyone can browse.

On a real site: an error page shows the full file path, database name and software version to anyone who triggers it. That's a map, handed to the attacker for free.

In our audit: Standard area 04 (configuration and patching). We review the server, TLS and headers, and probe for exposed files and admin panels.

A03 Software Supply Chain Failures

Your website is built from other people's code: plugins, themes, libraries, scripts loaded from somewhere else. When any one of them goes bad, it goes bad inside your site.

On a real site: a popular plugin is sold to a new owner, who pushes an "update" that quietly copies card details from the checkout page. Every site with automatic updates installs it overnight.

In our audit: Standard area 04 (patching) and 07 (suppliers and plugins). We inventory every component and check it against known-vulnerability databases.

A04 Cryptographic Failures

Sensitive data that isn't scrambled the way it should be. Once it leaks, it's readable.

On a real site: an old backup of the database sits in a public folder. The passwords inside are stored in a format that can be cracked in an afternoon, and most customers use the same password for their email.

In our audit: Standard area 06 (data protection). We check how passwords, backups and personal data are stored and transmitted.

A05 Injection

Someone types instructions into a box that was meant for plain text, and your site obeys them.

On a real site: a search box passes whatever it's given straight to the database. One carefully crafted search returns every customer email in the system. A comment field that accepts code lets an attacker run it in every visitor's browser.

In our audit: Standard area 05 (application security). We test every form, search box and parameter by hand and with tools.

A06 Insecure Design

The code works exactly as written. The plan was the problem. No patch fixes a feature that was unsafe on paper.

On a real site: a discount code can be applied fifty times to the same order. A "forgot password" page confirms which email addresses have accounts. A gift card balance can go negative. All working as designed.

In our audit: Standard area 02 (risk assessment) and 05 (application security). We walk through your key flows the way an abuser would.

A07 Authentication Failures

The login lets the wrong person in. Weak passwords, stolen passwords, sessions that never end.

On a real site: a bot tries a million leaked email-and-password pairs against your login page overnight. A few hundred of your customers reused a password. By morning the bot owns their accounts, and their saved addresses.

In our audit: Standard area 03 (access and passwords). We test login, password reset, sessions and logout, and review who holds which account.

A08 Software or Data Integrity Failures

Your site trusts something it never checked: a file, an update, a script, a piece of data that came back from the visitor's browser.

On a real site: the checkout page loads a script from a free hosting service. The service is compromised, the script is swapped, and your checkout starts sending payment details to someone else. Your own code never changed.

In our audit: Standard area 05 (change control) and 07 (suppliers). We review where your code and scripts come from and who can change them.

A09 Security Logging and Alerting Failures

Something bad happens and nobody notices. Not today, not next week. Breaches often go unspotted for months.

On a real site: a new admin account appears at 3 a.m. Nothing records it, nothing alerts anyone, and the first sign of trouble is a customer asking why your site is selling pills.

In our audit: Standard area 08 (logging and monitoring) and 09 (incident response). We trigger test events and see whether anyone hears about them.

A10 Mishandling of Exceptional Conditions

New on the 2025 list. When something unexpected happens, your site fails in an unsafe way: it lets people through instead of keeping them out.

On a real site: the payment provider times out, and the shop marks the order as paid anyway. The membership check errors out, and the site shows the members-only page to everyone.

In our audit: Standard area 05 (application security) and 10 (sound operations). We break things on purpose and watch which way the site falls.

0 / 30

Tick each statement that is true for your site.

Send my score for a free review

Here's the uncomfortable part.

A self-check measures what you believe about your website. Attackers test what's actually true.

Most website owners who tick "a customer can't see another customer's data" have never tried it. Most who tick "updates are applied" have a plugin nobody remembered. The gap between those two is where breaches live.

Our Certification Audit closes that gap. A real person tests your site against every one of these ten categories, plus the policies and habits around it, aligned with ISO/IEC 27001. You get a written report in plain English, a fix list ranked by risk, one free retest, and the Hacker Fortified Certified badge when the serious issues are gone.

Nobody ever wished they'd found the open door later.

Start a free written conversation

Questions

About the OWASP Top 10.

What is the OWASP Top 10?

It is a list of the ten most serious kinds of web application security risk, published by the OWASP Foundation, a nonprofit. It is updated every few years from real-world data. The current edition is the OWASP Top 10:2025. The descriptions on this page are our own plain-English summaries; the official list has the technical detail.

Does the OWASP Top 10 apply to a small website or a WordPress site?

Yes. If your site has a login, a form, a shop, plugins or customer data, every category on the list can apply to it. Attackers use automated tools that don't care how big you are.

Will a vulnerability scanner find all of these problems?

No. Scanners are good at outdated software and some misconfigurations. They are poor at broken access control and insecure design, which need a person who understands what your site is supposed to do. Those are the problems that cause the worst breaches.

Is a perfect self-check score the same as being secure?

No. The self-check shows you where the obvious gaps are. Only testing proves whether the controls you believe you have actually work. That is what a security audit is for.