v0.14 is out: a mobile auth pack for Swift/iOS and Android, catching insecure token storage, cleartext traffic, and OAuth in embedded WebViews. Read more →
OWASP COVERAGE

Mapped to the risks that matter.

Every OAuthLint rule maps to an OWASP risk. This page is built from the shipped rule pack, so it shows exactly which OWASP API Security and Web Application Top 10 categories the rules cover, and which auth anti-patterns sit under each.

11
OWASP categories covered
271
rules mapped to a risk
2
OWASP editions
API SECURITY TOP 10 · 2023
API1:2023 ↗ Broken Object Level Authorization 15 rules
API2:2023 ↗ Broken Authentication 102 rules
API7:2023 ↗ API7:2023 7 rules
API8:2023 ↗ Security Misconfiguration 56 rules
WEB APPLICATION TOP 10 · 2021
A01:2021 ↗ Broken Access Control 22 rules
A02:2021 ↗ Cryptographic Failures 37 rules
A05:2021 ↗ Security Misconfiguration 17 rules
A07:2021 ↗ Identification and Authentication Failures 9 rules
← all rules Coverage is derived from the shipped rule pack, so it grows with the rules.