Specifications
| Format | Learning |
|---|---|
| Level | Beginner, Intermediate, Advanced |
| Price | Free |
| Access | No registration |
| Activity | Active |
| Language | EN |
| Category | Secure code |
Secure coding lessons in the register of a developer reference: what a vulnerability is, the code shape it arrives in, and the fix that closes it. No challenges, no flag submission. The site advertises 45-plus lessons, recent ones covering LLM Slopsquatting, CSS Injection and CORS.
Pros & cons
Pros
- Written in developer language, without academic padding
- Shows the attack next to the line where your code goes wrong
- Open, no registration, readable as a reference rather than a course
Cons
- No practice anywhere: no tasks, no checker, no lab to break
- Topics sit side by side instead of forming a graded path
- The 45-plus lesson count is advertised, not maintained as an exact list
Who it fits
Suits a developer who wants to see where a flaw enters their own code. Not a trainer: it is reading, useful the hour before you start practising somewhere that actually checks you.
Getting started
- Read XSS and SQL injection first, everything else is measured against them
- Work through CORS and see how one misconfigured header sends data outward
- Take one LLM topic, slopsquatting for instance, and check it against a real model
History
Started as internal training and turned into a public set of secure coding lessons, with new topics still arriving. The front page advertises 45-plus lessons, which reads as marketing rather than a maintained index; the rest is free and open. Checked.