SECURITY REQUIREMENTS:
1. INPUT VALIDATION & SANITIZATION
– Sanitize and validate ALL user inputs on both frontend and backend.
– Prevent:
– SQL Injection
– NoSQL Injection
– XSS (Stored, Reflected, DOM)
– Command Injection
– LDAP Injection
– Template Injection
– Path Traversal
– File Upload Exploits
– Never trust client-side validation alone.
– Escape all outputs before rendering HTML.
– Strip dangerous HTML, scripts, inline events, and malicious payloads.
2. DATABASE SECURITY
– Use ONLY parameterized queries / prepared statements.
– NEVER concatenate SQL queries directly with user input.
– Use ORM safe methods where possible.
– Prevent mass assignment vulnerabilities.
– Hide database errors from users.
– Use least-privilege database accounts.
3. AUTHENTICATION & AUTHORIZATION
– Use secure authentication flows.
– Store passwords only with bcrypt or Argon2 hashing.
– Enforce:
– strong passwords
– rate limiting
– login throttling
– account lockout after repeated failures
– Use secure JWT/session handling.
– Sessions must use:
– HttpOnly cookies
– Secure flag
– SameSite protection
– Implement CSRF protection everywhere.
– Add optional 2FA support.
4. API SECURITY
– Validate every API request.
– Add API rate limiting.
– Prevent API abuse and brute force attacks.
– Use authentication middleware.
– Reject malformed JSON and oversized payloads.
– Never expose secrets or API keys in frontend code.
5. FILE UPLOAD SECURITY
– Allow only whitelisted file types.
– Validate MIME type and extension.
– Rename uploaded files securely.
– Store uploads outside executable directories.
– Scan uploads for malware if possible.
– Prevent double-extension attacks.
6. FRONTEND SECURITY
– Enable strict Content Security Policy (CSP).
– Disable inline JavaScript where possible.
– Prevent clickjacking using:
– X-Frame-Options
– frame-ancestors CSP
– Enable:
– X-Content-Type-Options
– Referrer-Policy
– Permissions-Policy
– Sanitize all dynamic HTML rendering.
– Avoid dangerous innerHTML usage.
7. BACKEND SECURITY
– Hide stack traces and internal server errors.
– Use centralized error handling.
– Implement audit logging.
– Add intrusion detection patterns.
– Prevent remote code execution vulnerabilities.
– Validate all headers, cookies, and request bodies.
– Block suspicious payloads and attack signatures.
8. SERVER & INFRASTRUCTURE SECURITY
– Force HTTPS everywhere.
– Enable HSTS.
– Disable directory listing.
– Secure CORS configuration.
– Disable unnecessary ports/services.
– Store secrets in environment variables only.
– Never hardcode passwords, API keys, or tokens.
– Add automatic security headers.
9. ANTI-BOT & DDOS PROTECTION
– Add CAPTCHA on sensitive forms.
– Add request throttling.
– Detect abnormal traffic behavior.
– Add bot protection middleware.
10. LOGGING & MONITORING
– Log:
– failed logins
– suspicious requests
– permission violations
– API abuse
– Never log passwords or sensitive personal data.
– Create security alerts for suspicious activities.
11. SECURE CODING RULES
– Follow OWASP Top 10 best practices.
– Follow secure-by-default architecture.
– Avoid vulnerable dependencies.
– Automatically check packages for vulnerabilities.
– Use TypeScript strict mode if applicable.
– Generate modular, maintainable, and secure code.
12. HEADERS TO ENABLE
– Content-Security-Policy
– Strict-Transport-Security
– X-Frame-Options
– X-Content-Type-Options
– Referrer-Policy
– Permissions-Policy
13. ADD SECURITY MIDDLEWARE
If using:
– Express.js → helmet, express-rate-limit, csurf
– Next.js → secure headers middleware
– Laravel → CSRF + validation middleware
– WordPress → nonce validation + sanitization + escaping
– React → sanitize dynamic content
– Node.js → validation middleware on every route
14. OUTPUT REQUIREMENTS
– Generate secure production-ready code.
– Explain every implemented security mechanism.
– Add comments describing anti-injection protections.
– Include examples of sanitized queries and secure API endpoints.
– Include secure authentication examples.
– Include secure upload handling examples.
– Include CSP configuration examples.
– Include rate-limiting examples.
– Include secure environment variable usage.
– Include anti-XSS rendering examples.
15. WORDPRESS/WOOCOMMERCE SECURITY (IF RELEVANT)
– Use:
– sanitize_text_field()
– esc_html()
– esc_attr()
– wp_nonce_field()
– check_admin_referer()
– wp_verify_nonce()
– prepare()
– Prevent direct access to PHP files.
– Protect AJAX endpoints.
– Validate REST API permissions.
– Escape ALL output properly.
– Prevent privilege escalation.
– Disable XML-RPC if unused.
16. FINAL SECURITY CHECK
Before final output:
– scan code for vulnerabilities
– check OWASP compliance
– validate secure headers
– verify injection protection
– verify authentication security
– verify authorization logic
– verify file upload protections
– verify API security
– verify session security
Generate the most secure architecture possible.
Security must be enabled by default, not optional.
החזון: להיות הטלפון הראשון שלך לעולם האינטרנט.
יזם ומוביל טכנולוגי מחזון ורעיון למוצר מתפקד ומוכר בשטח. פיתח מעל 15 מוצרים טכנולוגיים במהלך השנים וכיום מאות אתרים – בעיקר וורדפרס ו REACT – ומספר אפליקציות אינטרנט ייחודיות.
מתמחה בפיתוח אפליקציות, תוספים ותבניות, בניית אתרים, קידום אתרים, שיפורי אבטחה ואתרים מהירים. מחפש תמיד לעשות את המדויק, מקצועי ואם צריך שיהיה שונה מאחרים.