I was curious as to what makers are doing for testing the basic security of their app.
Do you hire someone?
Is there a tool in your particular framework that you use?
Security checklist?
Forget about it, ship?
I basically run through this list https://simplesecurity.sensedeep.com/web-developer-security-checklist-f2e4f43c9c56
Nice, I'll check this out. Thanks!
I recommend everyone to check out OWASP and specifically this checklist/cheat sheet: https://www.owasp.org/index.php/Web_Application_Security_Testing_Cheat_Sheet
OWASP is a great resource. They have a list of vulnerability scanning tools too: https://www.owasp.org/index.php/Category:Vulnerability_Scanning_Tools
I've used Zed Attack Proxy (ZAP) myself, it's open source and is actively maintained.
this is great, thanks!