Security
A manual code review based on the 2025 edition of the OWASP Top 10, complemented by analysis tools. Among other things, we look for:
- broken access control: who can see or change what, including cross-site request forgery (CSRF);
- security misconfiguration;
- software supply chain failures: vulnerable dependencies and components;
- cryptographic failures and information leaks;
- injection, including SQL injection and cross-site scripting (XSS);
- authentication failures.