Awarded for completing Cross-Site Scripting (XSS): Fundamentals and Defense and passing its exam, demonstrating the ability to explain how cross-site scripting works across its three classic categories, apply context-aware output encoding, evaluate Content Security Policy and session protections as complementary defenses, and review code and features for cross-site scripting risk.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.