Run this check →

New accounts start with 40 free credits.

Check code against the OWASP Top 10:2025

Web Application Security — OWASP Top 10:2025

Last updated: 29 September 2026

WHAT IT CHECKS

Source code, configuration and technical documents, against 132 security rules covering all ten OWASP Top 10:2025 categories — broken access control, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design, authentication failures, software or data integrity failures, security logging and alerting failures, and mishandling of exceptional conditions.

WHERE THE RULES COME FROM

OWASP's own Top 10:2025 category pages, plus one NIST document, so a few rules cite NIST rather than OWASP.

WHAT IT DOES NOT CHECK

  • Not a penetration test. It reviews what is written in the code and documents; it does not attack a running system.

WHAT YOU GET BACK

  • Each gap it finds, with the rule it fails and the source text that rule was taken from, quoted, so you can check it yourself.
  • Replacement wording for each finding, and a corrected copy of your document to download.
  • The pack's declared gaps, printed on every report, so you know what was not checked.

HOW TO RUN IT

In the browser. Sign in at https://vera.ink/verify, paste or upload the document, and choose this pack. New accounts start with 40 credits; a check costs 3 credits up to about 4,500 words.

From your AI assistant. vera.ink is an MCP server. Connect it to Claude Code or Cursor and ask your assistant to check a file against this pack: https://vera.ink/developers

GOOD TO KNOW

  • vera.ink only reports findings it can tie to a rule in this pack, and quotes the source text so you can check it. Anything it can't tie to a rule is dropped from the report.
  • It is a review aid, not legal advice or a certification. Read each finding before you act on it.

More checks: https://vera.ink/check