AppSec
In-depth guides and analysis on appsec from the Safeguard engineering team.
309 articles
Website Scanner: How It Works and What to Use
A website scanner probes a live site for security flaws like injection, misconfiguration, and known CVEs. Here is how the different scanner types work and when each one fits.
Code Vulnerability Scanning Tools: How to Choose the Right One
Code vulnerability scanning tools fall into distinct categories that see different risks. Knowing which does what is the difference between coverage and false confidence.
OWASP Top 10 and XSS: Where Cross-Site Scripting Fits Now
In the OWASP Top 10, XSS is no longer its own category. As of the 2021 list it lives inside A03: Injection. Here is what changed, why, and how to defend against it.
VAPT Services: What They Are and How to Choose One
VAPT services combine vulnerability assessment with penetration testing to both find weaknesses and prove which ones are actually exploitable. Here is what to expect and what to ask for.
react-quill and Quill: XSS History and Safe Rich-Text Editing
Using Quill in React means understanding CVE-2021-3163, the react-quill maintenance gap, and why editor output must always be sanitized server-side before display.
Dynamic Application Security Testing Tools, Compared
Dynamic application security testing tools test running applications the way an attacker would, but they differ sharply on API coverage, auth handling, and CI integration — here's how to tell them apart.
Report Scanner: How Vulnerability Scan Reports Work
A report scanner turns raw scan output into something a team can act on — deduplicated, prioritized, and mapped to owners — which is where most scanning programs actually stall.
OWASP Top 10 Certification: What It Actually Means
There is no official OWASP Top 10 certification, but here is how to prove OWASP Top 10 competence, which credentials cover it, and how teams demonstrate coverage.
API Security Posture Management, Explained
API security posture management inventories every API you actually have, then continuously checks it against the rules you meant to enforce.
Application Security Management: Programs That Actually Work
What separates an application security management program that actually reduces risk from one that just generates dashboards, based on where ownership and monitoring break down.
Apache Tomcat and Coyote Connector Vulnerabilities Explained
Apache tomcat vulnerabilities keep surfacing because Tomcat sits directly in the request path of so many Java applications; here is what the Coyote connector does and which vulnerability classes recur most.
How a Source Code Security Scanner Works and Which One to Use
A source code security scanner reads your code without running it to find injection, secrets, and logic flaws. Here is how the analysis works and how to pick one that fits.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.