Skip to content
All articles
Security

Django Security Checklist Before You Go Live

Ten settings and habits that protect your Django project from the most common attacks.

Temurbek Murotov 1 min read

Django is secure by default, but a few settings must be changed before production. Run python manage.py check --deploy and go through this list.

Settings

  1. DEBUG = False — never expose stack traces.
  2. Keep SECRET_KEY in an environment variable, never in Git.
  3. Set ALLOWED_HOSTS explicitly.
  4. SECURE_SSL_REDIRECT = True and SECURE_HSTS_SECONDS = 31536000.
  5. SESSION_COOKIE_SECURE = True and CSRF_COOKIE_SECURE = True.

Habits

  1. Never build SQL with string formatting. Use the ORM or query parameters.
  2. Escape output. Avoid |safe and mark_safe on user input.
  3. Validate uploads — check size and type, and never serve them from the app domain without care.
  4. Rate-limit login and forms (e.g. django-axes or DRF throttling).
  5. Keep dependencies updated — pip list --outdated and GitHub Dependabot.

Admin

Move the admin from /admin/ to a non-obvious URL, enforce strong passwords and consider 2FA with django-otp.

Security is not a one-time task, but these ten points close the doors most attackers try first.

  • #django
  • #security
  • #best-practices
Share:

Related articles

Have a project in mind?

Let’s turn your idea into a reliable product. The first consultation and estimate are free.