Checklist
GraphQL Security Testing Checklist
GraphQL gives development teams a flexible way to build and connect modern applications. But that flexibility can also introduce security risks that are easy to miss.
The GraphQL Security Testing Checklist gives security and development teams a practical framework for reviewing common GraphQL security controls and vulnerabilities.
Use this checklist to test for:
- Authentication and authorization weaknesses
- BOLA, BFLA, and resolver-level access control issues
- Injection and unsafe mutations
- Introspection and schema exposure
- Query depth, batching, and denial-of-service risks
- Error leakage and insecure file handling
- Subscription and persisted query security
Use it as a repeatable guide for validating GraphQL APIs before they reach production.