Awarded for completing Server-Side Template Injection and passing its exam, demonstrating the ability to explain how server-side template injection differs from cross-site scripting, recognize the vulnerable pattern of concatenating untrusted input into a template definition, apply the data and code separation fix, assess severity based on a templating engine's exposed capability, evaluate the honest limits of sandboxed execution modes, and build a review and response program that catches this vulnerability class deliberately.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.