Skip to content
Back to skills

Web Testing Checklist

ASecurity

A fast, ordered checklist for testing a web application end to end — so nothing gets skipped. Load when starting on a web target, "checklist", "what should I test", methodology triage, or to confirm coverage before reporting. Signals: a new web app in scope, "am I missing anything".

  • 20 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 22, 2026
ai-agentsgosqlawstesting

Works with

  • cli

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill web-testing-checklist --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Web Testing Checklist?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Web Testing Checklist
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-web-testing-checklist/badge)](https://www.skillsdirectory.com/skills/noorqureshi-web-testing-checklist)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: web-testing-checklist
description: >
  A fast, ordered checklist for testing a web application end to end — so nothing gets skipped.
  Load when starting on a web target, "checklist", "what should I test", methodology triage, or
  to confirm coverage before reporting. Signals: a new web app in scope, "am I missing anything".
domain: web
type: checklist
stability: learning
modes: [bugbounty, pentest]
severity: info
schema_version: 1
---

# Web application testing checklist

Work top to bottom; each item links to the skill that goes deep. Confirm scope first
(`tradecraft-scope-roe`).

## Recon & mapping
- [ ] Subdomains + live hosts (`recon-subdomain-enum`), DNS (`recon-dns-analysis`)
- [ ] Content/endpoint + param discovery (`recon-content-discovery`), JS mining (`recon-js-analysis`)
- [ ] Fingerprint stack/versions; note WAF/CDN (`web-arsenal`)

## Authentication & session
- [ ] Login/registration flaws, username enumeration, rate limiting
- [ ] Password reset & email change (`web-account-takeover`), OTP/2FA bypass
- [ ] Session handling & JWT (`web-auth-jwt`); OAuth/SSO (`web-oauth`)

## Authorization
- [ ] IDOR / object-level (`web-idor`); function-level / forced browsing
- [ ] Multi-tenant boundary crossing

## Input handling (injection & rendering)
- [ ] XSS reflected/stored/DOM (`web-xss`, `payloads-xss-polyglots`)
- [ ] SQLi (`web-sqli`), NoSQLi; SSTI (`web-ssti`); command injection
- [ ] SSRF (`web-ssrf`); XXE (`web-xxe`); LFI/traversal (`web-lfi-path-traversal`)
- [ ] Deserialization (`web-deserialization`); prototype pollution (`web-prototype-pollution`)

## App logic & client
- [ ] Business logic (`web-business-logic`); race conditions (`web-race-conditions`)
- [ ] File upload (`web-file-upload`); CSRF (`web-csrf`); CORS (`web-cors`); open redirect (`web-open-redirect`)
- [ ] Host-header/cache (`web-cache-poisoning`), request smuggling (`web-request-smuggling`)

## Before reporting
- [ ] Impact proven & reproducible; evidence captured; severity set (`reporting-bug-bounty-writeup`)
- [ ] In scope, within RoE; no real data hoarded

## Notes
A checklist is a coverage aid, not a substitute for judgment — follow the leads that look weird.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…