HackSplaining

Visit platform ↗

FreeAll levelsActive

Specifications

Specifications
FormatLearning
LevelBeginner, Intermediate, Advanced
PriceFree
AccessNo registration
ActivityActive
LanguageEN
CategorySecure code

Secure coding lessons in the register of a developer reference: what a vulnerability is, the code shape it arrives in, and the fix that closes it. No challenges, no flag submission. The site advertises 45-plus lessons, recent ones covering LLM Slopsquatting, CSS Injection and CORS.

Pros & cons

Pros

  • Written in developer language, without academic padding
  • Shows the attack next to the line where your code goes wrong
  • Open, no registration, readable as a reference rather than a course

Cons

  • No practice anywhere: no tasks, no checker, no lab to break
  • Topics sit side by side instead of forming a graded path
  • The 45-plus lesson count is advertised, not maintained as an exact list

Who it fits

Suits a developer who wants to see where a flaw enters their own code. Not a trainer: it is reading, useful the hour before you start practising somewhere that actually checks you.

Getting started

  1. Read XSS and SQL injection first, everything else is measured against them
  2. Work through CORS and see how one misconfigured header sends data outward
  3. Take one LLM topic, slopsquatting for instance, and check it against a real model

History

Started as internal training and turned into a public set of secure coding lessons, with new topics still arriving. The front page advertises 45-plus lessons, which reads as marketing rather than a maintained index; the rest is free and open. Checked.