
Resources / Checklists /
Web Application Security
DOCX
Web Application and API Security Self-Assessment Checklist: OWASP-Mapped Test Cases
Over 200 web test cases mapped to the OWASP Top 10 2021, plus API checklists for the 2019 and 2023 OWASP API Security Top 10, so you test against a standard, not an ad-hoc list.
Format:
DOCX
Last updated:
September 16, 2026
Read time:
5
min
A web application review is only as good as its coverage, and testing whatever comes to mind misses the categories an attacker won't. This checklist anchors every test case to a published standard, the OWASP Top 10 for web and the OWASP API Security Top 10 for APIs, so nothing is there by accident and nothing important is left off.
Each row is one test case with a Payatu identifier, grouped by OWASP category, with columns for your observation and a pass, fail, or NA status. The workbook separates web from API and keeps both the 2019 and 2023 API Top 10 editions, so you can test against whichever your program references.
Key Takeaways
- The web checklist maps over 200 test cases to the OWASP Top 10 2021, with the heaviest coverage on Injection, Authentication, Session and MFA Failures, Insecure Design, and Broken Access Control.
- Two separate API checklists: one mapped to the OWASP API Security Top 10 2019, one to the 2023 edition, so you can align to either version.
- The 2023 API sheet ties test cases to CWE identifiers, connecting each check to the underlying weakness.
- Every test case carries a Payatu identifier and a Pass, Fail, or NA status column, so the filled workbook is a repeatable assessment record, not a one-time list.
- Built on OWASP's Web Security Testing Guide methodology, referenced in the workbook.
What's Inside
Separate sheets for the application and the APIs behind it.
- A web checklist, every row one test case with a PY-Web identifier, grouped by OWASP Top 10 2021 category: Reconnaissance, Injection, Broken Access Control, Cryptographic Failures, Security Misconfiguration, Insecure Design, Vulnerable and Outdated Components, Authentication/Session/MFA Failures, Software and Data Integrity Failures, Security Logging and Monitoring Failures, SSRF, and a Miscellaneous section for app-specific cases.
- An API checklist mapped to the OWASP API Security Top 10 2019: broken access control, authentication, rate limiting, injection, and more.
- A second API checklist mapped to the OWASP API Security Top 10 2023, with CWE references: BOLA, broken authentication, SSRF, unsafe consumption of APIs, and the rest of the 2023 list.
- Observation and Pass/Fail/NA columns on every row.
How to use it
01
Pick the sheet. The web checklist for the application, API 2019 or 2023 for the APIs behind it.
02
Read across the row. The Payatu identifier and OWASP category, the test case, and, on the 2023 API sheet, the CWE it maps to.
03
Record your result. Note the observation and set Pass, Fail, or NA on each row so the workbook becomes your assessment evidence.
04
Want the findings validated by hand? Payatu's application security team runs these test cases manually, past the scanner's reach, in a scoped web or API assessment. Get a scoped assessment.
Subscribe to our newsletter
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Reviewed by

Web App Security Team








