Checklist of the most important security countermeasures when designing, testing, and releasing your API
active 2025-02-20 → 2026-07-21 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 517 days from 2025-02-20 to 2026-07-21. Pushes: 5 total, peak 1 in a day. Pull requests: 4 total, peak 1 in a day. Issues: 10 total, peak 9 in a day. Comments: 18 total, peak 10 in a day. Stars: 316 total, peak 16 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| Maikuolan | 28 | 5 | 1 | 9 |
| guest20 | 4 | 0 | 0 | 3 |
| bad-antics | 4 | 0 | 1 | 3 |
| sethherr | 2 | 0 | 1 | 1 |
| 17lilb | 2 | 0 | 0 | 1 |
| Safe3 | 1 | 0 | 0 | 0 |
| andrealungh1 | 1 | 0 | 1 | 0 |
| krnssilka | 1 | 0 | 0 | 1 |
Recent activity
Latest issues, pull requests and releases
- Pull request#213sethherr2026-02-03 06:23
- Issue#6Maikuolan2026-02-03 05:41Don't recommend JWT
- Issue comment#6Maikuolan2026-02-03 05:41Don't recommend JWT
- Issue#179Maikuolan2026-02-03 05:33Expand on the authentication suggestion
- Issue comment#179Maikuolan2026-02-03 05:33Expand on the authentication suggestion
- Issue comment#174Maikuolan2026-02-03 05:33HTTP Headers
- Issue#170Maikuolan2026-02-03 05:32request integrity & replay
- Issue comment#170Maikuolan2026-02-03 05:32request integrity & replay
- Issue comment#25Maikuolan2026-02-03 05:32Suggestion: Always set charset in response header
- Issue#25Maikuolan2026-02-03 05:32Suggestion: Always set charset in response header
- Issue#11Maikuolan2026-02-03 05:32Why no word about range, type and length checks?
- Issue#153Maikuolan2026-02-03 05:32JWT token should be stored securely if they are used as auth for browser users.
- Issue comment#153Maikuolan2026-02-03 05:32JWT token should be stored securely if they are used as auth for browser users.
- Issue#119Maikuolan2026-02-03 05:31Should mention CORS
- Issue comment#119Maikuolan2026-02-03 05:31Should mention CORS
- Issue#27Maikuolan2026-02-03 05:30Correlation with external (prior) guidelines
- Issue#210Maikuolan2026-02-03 05:29Suggest a powerful free and open source WAF - UUSEC WAF
- Issue comment#210Maikuolan2026-02-03 05:29Suggest a powerful free and open source WAF - UUSEC WAF
- Issue comment#212bad-antics2026-02-03 03:06Add advanced API security best practices
- Issue comment#212bad-antics2026-01-28 21:51Add advanced API security best practices
- Issue comment#212bad-antics2026-01-27 19:47Add advanced API security best practices
- Pull request#212bad-antics2026-01-26 19:20
- Issue comment#189krnssilka2025-08-23 03:06Security Headers
- Pull request#211andrealungh12025-08-12 23:35
- Pull request#208Maikuolan2025-05-07 02:37
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 316 stars here means stars gained during the window, not the repo's star count.