{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T08:51:20Z","timestamp":1776329480752,"version":"3.50.1"},"reference-count":82,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T00:00:00Z","timestamp":1775088000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Computers"],"abstract":"<jats:p>The challenge of software vulnerabilities persists globally, despite the widespread availability of advanced security tools and comprehensive developer guidelines. This issue is not the result of professional negligence, but rather the complex and non-intuitive nature of secure coding. This research takes on the massive data silos in the security industry by providing a comprehensive review of best practices drawn from 35 reputable academic and corporate sources. Authentication, cryptography, input validation, and deployment hardening are some of the key development domains into which these technologies are organized. We conduct a comprehensive analysis of each practice, elucidating the specific security issue it addresses, prevalent implementation patterns, and potential hazards, in addition to serving as a checklist. Simple precautions, like not using passwords that are hardcoded, and more involved methods, such correctly encoding output and configuring access controls effectively, are all part of the range of practices. We assert that despite the prevalent usage of tools like as static analyzers, numerous vulnerabilities persist due to developers\u2019 insufficient training in integrating security considerations into their coding practices. This work aspires to serve as a comprehensive, organized resource that supplies developers with the necessary context and guidance to make informed, security-oriented decisions along the software development lifecycle. The aim is to develop a more extensive resource than those presently accessible, which can also assist educators or security teams during code instruction or evaluation.<\/jats:p>","DOI":"10.3390\/computers15040220","type":"journal-article","created":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T14:09:54Z","timestamp":1775138994000},"page":"220","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Toward a Unified Framework for Secure Coding: A Comprehensive Synthesis of Best Practices"],"prefix":"10.3390","volume":"15","author":[{"given":"Alyah","family":"Alromaizan","sequence":"first","affiliation":[{"name":"Department of Software Engineering, Alfaisal University, Riyadh 11533, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ghala","family":"Alzahrani","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Alfaisal University, Riyadh 11533, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aliza","family":"Khan","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Alfaisal University, Riyadh 11533, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lulwah","family":"Alhumaid","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Alfaisal University, Riyadh 11533, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9986-210X","authenticated-orcid":false,"given":"Md Kamrul","family":"Siam","sequence":"additional","affiliation":[{"name":"Department of Computer Science, New York Institute of Technology, New York, NY 10023, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6939-6929","authenticated-orcid":false,"given":"Muhammad Umair","family":"Khan","sequence":"additional","affiliation":[{"name":"Department of Software Engineering, Alfaisal University, Riyadh 11533, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6316-5334","authenticated-orcid":false,"given":"Md Jobair Hossain","family":"Faruk","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of Central Arkansas, Conway, AR 72035, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1021-7986","authenticated-orcid":false,"given":"Hossain","family":"Shahriar","sequence":"additional","affiliation":[{"name":"Center for Cybersecurity, University of West Florida, Pensacola, FL 32514, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2026,4,2]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Alenezi, M., and Zarour, M. (2020). On the relationship between software complexity and security. arXiv.","DOI":"10.5121\/ijsea.2020.11104"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mulahuwaish, A., Qolomany, B., Gyorick, K., Abdo, J.B., Aledhari, M., Qadir, J., Carley, K., and Al-Fuqaha, A. (2025). A survey of social cybersecurity: Techniques for attack detection, evaluations, challenges, and future prospects. Comput. Hum. Behav. Rep., 18.","DOI":"10.1016\/j.chbr.2025.100668"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Siam, M.K., Saha, B., Hasan, M.M., Hossain Faruk, M.J., Anjum, N., Tahora, S., Siddika, A., and Shahriar, H. (2025). Securing Decentralized Ecosystems: A Comprehensive Systematic Review of Blockchain Vulnerabilities, Attacks, and Countermeasures and Mitigation Strategies. Future Internet, 17.","DOI":"10.3390\/fi17040183"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Fredj, O.B., Cheikhrouhou, O., Krichen, M., Hamam, H., and Derhab, A. (2020). An OWASP top ten driven survey on web application protection methods. Proceedings of the International Conference on Risks and Security of Internet and Systems, Springer.","DOI":"10.36227\/techrxiv.13265180"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Kioskli, K., Grigoriou, E., Islam, S., Yiorkas, A.M., Christofi, L., and Mouratidis, H. (2025). A risk and conformity assessment framework to ensure security and resilience of healthcare systems and medical supply chain. Int. J. Inf. Secur., 24.","DOI":"10.1007\/s10207-025-01009-z"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"1419","DOI":"10.1007\/s10664-019-09750-5","article-title":"How developers engage with static analysis tools in different contexts","volume":"25","author":"Vassallo","year":"2020","journal-title":"Empir. Softw. Eng."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Wendt, D.W. (2025). Regulations, Standards, and Frameworks. AI Strategy and Security: A Roadmap for Secure, Responsible, and Resilient AI Adoption, Apress.","DOI":"10.1007\/979-8-8688-1733-5"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Acar, Y., Stransky, C., Wermke, D., Weir, C., Mazurek, M.L., and Fahl, S. (2017, January 24\u201326). Developers need support, too: A survey of security advice for software developers. Proceedings of the 2017 IEEE Cybersecurity Development (SecDev), Cambridge, MA, USA.","DOI":"10.1109\/SecDev.2017.17"},{"key":"ref_9","unstructured":"Hove, S. (2025). Exploring Factors Influencing the Integration of Secure Code Development Protocols Within the Software Development Lifecycle. [Ph.D. Thesis, Capella University]."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"13919","DOI":"10.1109\/ACCESS.2025.3528960","article-title":"Advancing passwordless authentication: A systematic review of methods, challenges, and future directions for secure user identity","volume":"13","author":"Yusop","year":"2025","journal-title":"IEEE Access"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Altulaihan, E.A., Alismail, A., and Frikha, M. (2023). A survey on web application penetration testing. Electronics, 12.","DOI":"10.3390\/electronics12051229"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Newhouse, B., Souppaya, M., Cooper, D., Polk, T., Barker, W., Scarfone, K., Kent, J., Sexton, J., Dimond, M., and Klosterman, J. (2025). Addressing Visibility Challenges with TLS 1.3 within the Enterprise High-Level Document. NIST Spec. Publ., 1800.","DOI":"10.6028\/NIST.SP.1800-37"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Rauf, I., Lopez, T., Sharp, H., Petre, M., Tun, T., Levine, M., Towse, J., van der Linden, D., Rashid, A., and Nuseibeh, B. (2022, January 18\u201319). Influences of developers\u2019 perspectives on their engagement with security in code. Proceedings of the 15th International Conference on Cooperative and Human Aspects of Software Engineering, Pittsburgh, PA, USA.","DOI":"10.1145\/3528579.3529180"},{"key":"ref_14","unstructured":"Gasiba, T.E., Pereira, J.M., de Oliveira, L.C., and Murta, D.L.P. (2021, January 25\u201328). Is secure coding education in the industry needed?. Proceedings of the 43rd International Conference on Software Engineering: Software Engineering Education and Training (ICSE-SEET), Madrid, Spain."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Yang, Y., Wu, Y., Pattabiraman, K., Wang, L., and Li, Y. (2020, January 12\u201315). How far have we come in detecting anomalies in distributed systems? An empirical study with a statement-level fault injection method. Proceedings of the IEEE 31st International Symposium on Software Reliability Engineering (ISSRE), Coimbra, Portugal.","DOI":"10.1109\/ISSRE5003.2020.00015"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Lopez, T., Sharp, H., Tun, T., Bandara, A., Levine, M., and Nuseibeh, B. (2019, January 27). \u201cHopefully We Are Mostly Secure\u201d: Views on Secure Code in Professional Practice. Proceedings of the 2019 IEEE\/ACM 12th International Workshop on Cooperative and Human Aspects of Software Engineering (CHASE), Montreal, QC, Canada.","DOI":"10.1109\/CHASE.2019.00023"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Oh, S., Srivastava, A., Mirhosseini, A., Yoon, J., Roesner, F., and Kohno, T. (2024, January 19\u201323). Poisoned ChatGPT finds work for idle hands: Exploring developers\u2019 coding practices with insecure suggestions from poisoned AI models. Proceedings of the IEEE Symposium on Security and Privacy (S&P), San Francisco, CA, USA.","DOI":"10.1109\/SP54263.2024.00046"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Perry, N., Suresh, S., Nair, A., Zorn, B., Livshits, B., and Tarlow, D. (2022). Do users write more insecure code with AI assistants?. arXiv.","DOI":"10.1145\/3576915.3623157"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3687299","article-title":"A systematic literature review on the influence of enhanced developer experience on developers\u2019 productivity: Factors, practices, and recommendations","volume":"57","author":"Razzaq","year":"2024","journal-title":"ACM Comput. Surv."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1145\/3610721","article-title":"Asleep at the keyboard? Assessing the security of github copilot\u2019s code contributions","volume":"68","author":"Pearce","year":"2025","journal-title":"Commun. ACM"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Perry, N., Srivastava, M., Kumar, D., and Boneh, D. (2023, January 26\u201330). Do users write more insecure code with ai assistants?. Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, Copenhagen, Denmar.","DOI":"10.1145\/3576915.3623157"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Aghakhani, H., Dai, W., Manoel, A., Fernandes, X., Kharkar, A., Kruegel, C., Vigna, G., Evans, D., Zorn, B., and Sim, R. (2023). TrojanPuzzle: Covertly Poisoning Code-Suggestion Models. arXiv.","DOI":"10.1109\/SP54263.2024.00140"},{"key":"ref_23","unstructured":"Chung, S., and Endicott-Popovsky, B. (July, January 29). Software reengineering based security teaching. Proceedings of the International Conference on Cybernetics and Information Technologies, Systems and Applications (CITSA), Orlando, FL, USA."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Nembhard, F.D., Carvalho, M.M., and Eskridge, T.C. (2019). Towards the application of recommender systems to secure coding. EURASIP J. Inf. Secur., 2019.","DOI":"10.1186\/s13635-019-0092-4"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Ryan, I., Roedig, U., and Stol, K.J. (2024, January 15). Training developers to code securely: Theory and practice. Proceedings of the ACM\/IEEE International Conference on Engineering Secure Software and Systems (EnCyCriS), Lisbon, Portugal.","DOI":"10.1145\/3643662.3643956"},{"key":"ref_26","unstructured":"Meng, N., Nagappan, M., Bird, C., and Zimmermann, T. (June, January 27). Secure coding practices in Java: Challenges and vulnerabilities. Proceedings of the 40th International Conference on Software Engineering (ICSE), Gothenburg, Sweden."},{"key":"ref_27","unstructured":"Votipka, D., Rabinovitch, A., Redmiles, E., Mazurek, P., and Mazurek, M.L. (2020, January 12\u201314). Understanding security mistakes developers make: Qualitative analysis from Build It, Break It, Fix It. Proceedings of the USENIX Security Symposium, Boston, MA, USA."},{"key":"ref_28","unstructured":"Grassi, P.A., Garcia, M.E., and Fenton, J.L. (2017). Digital Identity Guidelines: Authentication and Lifecycle Management, Technical Report SP 800-63B."},{"key":"ref_29","unstructured":"MITRE (2026, February 16). CWE-521: Weak Password Requirements. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/521.html."},{"key":"ref_30","unstructured":"MITRE (2026, February 16). CWE-798: Use of Hard-Coded Credentials. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/798.html."},{"key":"ref_31","unstructured":"MITRE (2026, February 16). CWE-307: Improper Restriction of Excessive Authentication Attempts. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/307.html."},{"key":"ref_32","unstructured":"MITRE (2026, February 16). CWE-1188: Insecure Default Initialization of Resource. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1188.html."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Black, P., Guttman, B., and Okun, V. (2021). Guidelines on Minimum Standards for Developer Verification of Software, NIST Interagency or Internal Report (IR) 8397.","DOI":"10.6028\/NIST.IR.8397"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Rahayu, S.B., Ahmad, A.R., and Rashid, Z. (2022). Defensive programming: Developing a web application with secure coding practices. AIP Conf. Proc., 2617.","DOI":"10.1063\/5.0119726"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Loncar, K., Borsic, M., and Dukic, M. (2024, January 24\u201325). Secure coding guidelines and standards. Proceedings of the 35th DAAAM International Symposium on Intelligent Manufacturing and Automation, Vienna, Austria.","DOI":"10.2507\/35th.daaam.proceedings.025"},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Weir, C., Ozment, A., and Seaman, C.B. (2018, January 20\u201324). Light-touch interventions to improve software development security. Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SecDev.2018.00019"},{"key":"ref_37","unstructured":"Nguyen, D., Kayes, A.M.M., Babar, M.A., Cavallaro, L., and Lo, D. (3\u2013November, January 30). A stitch in time: Supporting Android developers in writing secure code. Proceedings of the ACM Conference on Computer and Communications Security (CCS), Dallas, TX, USA."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Zeng, M., and Zhu, F. (2021). Secure coding in five steps. J. Cybersecur. Educ. Res. Pract., 2021.","DOI":"10.62915\/2472-2707.1076"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"dos Santos, R.M., and Gerosa, M.A. (2018, January 28\u201329). Impacts of coding practices on readability. Proceedings of the 26th Conference on Program Comprehension, Gothenburg, Sweden.","DOI":"10.1145\/3196321.3196342"},{"key":"ref_40","first-page":"48","article-title":"Writing secure code in the digital age: Preventing common vulnerabilities","volume":"185","author":"Thatikonda","year":"2023","journal-title":"Int. J. Comput. Appl."},{"key":"ref_41","unstructured":"MITRE (2026, February 16). CWE-320: Use of Hard-Coded Cryptographic Key. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/320.html."},{"key":"ref_42","unstructured":"MITRE (2026, February 16). CWE-547: Use of Hard-Coded, Security-Relevant Constants. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/547.html."},{"key":"ref_43","unstructured":"MITRE (2026, February 16). CWE-1102: Reliance on Machine-Dependent Data Representation. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1102.html."},{"key":"ref_44","unstructured":"MITRE (2026, February 16). CWE-1127: Compilation with Insufficient Warnings or Errors. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1127.html."},{"key":"ref_45","unstructured":"MITRE (2026, February 16). CWE-330: Use of Insufficiently Random Values. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/330.html."},{"key":"ref_46","first-page":"34","article-title":"Implementing secure and efficient code in system software development","volume":"15","author":"Sheta","year":"2024","journal-title":"Int. J. Inf. Technol. Manag. Inf. Syst."},{"key":"ref_47","unstructured":"MITRE (2026, February 16). CWE-478: Missing Default Case in Multiple Condition Expression. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/478.html."},{"key":"ref_48","unstructured":"MITRE (2026, February 16). CWE-1104: Use of Unmaintained Third Party Components. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1104.html."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Chowdhury, M.N.U.R., Chowdhury, F.H., and Kayes, A.S.M. (2024, January 12\u201313). AI-driven secure coding: Revolutionizing source code defense. Proceedings of the IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS), Lucknow, India.","DOI":"10.1109\/SPARC61891.2024.10828840"},{"key":"ref_50","unstructured":"MITRE (2026, February 16). CWE-605: Multiple Binds to the Same Port. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/605.html."},{"key":"ref_51","unstructured":"MITRE (2026, February 16). CWE-1101: Insufficient Isolation of System-Dependent Functions. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1101.html."},{"key":"ref_52","unstructured":"NIST National Vulnerability Database (2026, February 16). CVE-2021-22005 Detail, Available online: https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2021-22005."},{"key":"ref_53","unstructured":"MITRE (2026, February 16). CWE-548: Exposure of Information Through Directory Listing. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/548.html."},{"key":"ref_54","unstructured":"MITRE (2026, February 16). CWE-487: Exposure of System Data to an Unauthorized Control Sphere. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/487.html."},{"key":"ref_55","unstructured":"MITRE (2026, February 16). CWE-358: Improperly Unlocked Resource. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/358.html."},{"key":"ref_56","unstructured":"MITRE (2026, February 16). CWE-1235: Data Element Aggregating an Excessively Large Number of Non-Primitive Elements. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1235.html."},{"key":"ref_57","unstructured":"MITRE (2026, February 16). CWE-119: Improper Restriction of Operations Within the Bounds of a Memory Buffer. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/119.html."},{"key":"ref_58","unstructured":"MITRE (2026, February 16). CWE-404: Improper Resource Shutdown or Release. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/404.html."},{"key":"ref_59","unstructured":"White, G. (2015). Secure Coding Practices, Tools, and Processes, Technical Report LLNL-CONF-671591."},{"key":"ref_60","unstructured":"Turner, S. (2026, February 16). Security Vulnerabilities of the Top Ten Programming Languages: C, Java, C++, Objective-C, C#, PHP, Visual Basic, Python, Perl, and Ruby. Academic and Business Research Institute (AABRI). Available online: https:\/\/www.aabri.com\/LV2013Manuscripts\/LV13090.pdf."},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Anis, A., Zulkernine, M., Iqbal, S., Liem, C., and Chambers, C. (2018, January 12\u201315). Securing Web Applications with Secure Coding Practices and Integrity Verification. Proceedings of the 2018 IEEE 16th International Conference on Dependable, Autonomic and Secure Computing, 16th International Conference on Pervasive Intelligence and Computing, 4th International Conference on Big Data Intelligence and Computing, and Cyber Science and Technology Congress (DASC\/PiCom\/DataCom\/CyberSciTech), Athens, Greece.","DOI":"10.1109\/DASC\/PiCom\/DataCom\/CyberSciTec.2018.00112"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Ryan, I., Roedig, U., and Stol, K.J. (2023, January 14\u201320). Measuring Secure Coding Practice and Culture: A Finger Pointing at the Moon is not the Moon. Proceedings of the 2023 IEEE\/ACM 45th International Conference on Software Engineering (ICSE), Melbourne, VIC, Australia.","DOI":"10.1109\/ICSE48619.2023.00140"},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Smith, J.M., and Schuchard, M. (2018, January 21\u201323). Routing Around Congestion: Defeating DDoS Attacks and Adverse Network Conditions via Reactive BGP Routing. Proceedings of the 2018 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2018.00032"},{"key":"ref_64","unstructured":"MITRE (2026, February 16). CWE-489: Active Debug Code. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/489.html."},{"key":"ref_65","unstructured":"MITRE (2026, February 16). CWE-248: Uncaught Exception. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/248.html."},{"key":"ref_66","unstructured":"MITRE (2026, February 16). CWE-209: Generation of Error Message Containing Sensitive Information. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/209.html."},{"key":"ref_67","unstructured":"MITRE (2026, February 16). CWE-532: Insertion of Sensitive Information into Log File. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/532.html."},{"key":"ref_68","unstructured":"MITRE (2026, February 16). CWE-215: Insertion of Sensitive Information into Debugging Output. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/215.html."},{"key":"ref_69","doi-asserted-by":"crossref","first-page":"31","DOI":"10.30564\/jcsr.v4i2.4048","article-title":"Optimization of Secure Coding Practices in SDLC as Part of Cybersecurity Framework","volume":"4","author":"Jakimoski","year":"2022","journal-title":"J. Comput. Sci. Res."},{"key":"ref_70","unstructured":"MITRE (2026, February 16). CWE-807: Reliance on Untrusted Inputs in a Security Decision. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/807."},{"key":"ref_71","unstructured":"MITRE (2026, February 16). CWE-1092: Use of Same Invokable Control Element in Multiple Architectural Layers. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1092.html."},{"key":"ref_72","unstructured":"MITRE (2026, February 16). CWE-1099: Missing Handler for Support of Multiple International Standards. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1099.html."},{"key":"ref_73","unstructured":"MITRE (2026, February 16). CWE-1116: Inaccurate Comments. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1116.html."},{"key":"ref_74","unstructured":"MITRE (2026, February 16). CWE-502: Deserialization of Untrusted Data. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/502.html."},{"key":"ref_75","unstructured":"MITRE (2026, February 16). CWE-611: Improper Restriction of XML External Entity Reference. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/611.html."},{"key":"ref_76","unstructured":"MITRE (2026, February 16). CWE-20: Improper Input Validation. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/20.html."},{"key":"ref_77","unstructured":"MITRE (2026, February 16). CWE-770: Allocation of Resources Without Limits or Throttling. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/770.html."},{"key":"ref_78","unstructured":"Murphy, T. (2010). Security Challenges in the 21st Century Global Commons. Yale J. Int. Aff., 5."},{"key":"ref_79","unstructured":"MITRE (2026, February 16). CWE-1117: Inclusion of Undocumented Features or APIs. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1117.html."},{"key":"ref_80","unstructured":"MITRE (2026, February 16). CWE-840: Improper Neutralization of Delimiters in Controls in a Business Flow. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/840.html."},{"key":"ref_81","unstructured":"MITRE (2026, February 16). CWE-1021: Improper Restriction of Rendered UI Layers or Frames. Common Weakness Enumeration. Available online: https:\/\/cwe.mitre.org\/data\/definitions\/1021.html."},{"key":"ref_82","unstructured":"Foundation, O. (2026, February 16). OWASP Juice Shop\u2014The Most Insecure Web Application for Security Training. Available online: https:\/\/owasp.org\/www-project-juice-shop\/."}],"container-title":["Computers"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/4\/220\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T07:46:12Z","timestamp":1776325572000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-431X\/15\/4\/220"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,2]]},"references-count":82,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,4]]}},"alternative-id":["computers15040220"],"URL":"https:\/\/doi.org\/10.3390\/computers15040220","relation":{},"ISSN":["2073-431X"],"issn-type":[{"value":"2073-431X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,2]]}}}