Secure coding for web applications: Frameworks, challenges, and the role of LLMs

Kiana Kiashemshaki, Mohammad Jalili Torkamani, Negin Mahmoudi

公開日: 2025/7/29

Abstract

Secure coding is a critical yet often overlooked practice in software development. Despite extensive awareness efforts, real-world adoption remains inconsistent due to organizational, educational, and technical barriers. This paper provides a comprehensive review of secure coding practices across major frameworks and domains, including web development, DevSecOps, and cloud security. It introduces a structured framework comparison and categorizes threats aligned with the OWASP Top 10. Additionally, we explore the rising role of Large Language Models (LLMs) in evaluating and recommending secure code, presenting a reproducible case study across four major vulnerability types. This paper offers practical insights for researchers, developers, and educators on integrating secure coding into real-world development processes.

Secure coding for web applications: Frameworks, challenges, and the role of LLMs | SummarXiv | SummarXiv