Django Security Checklist Before You Go Live
Ten settings and habits that protect your Django project from the most common attacks.
Django is secure by default, but a few settings must be changed before production. Run python manage.py check --deploy and go through this list.
Settings
DEBUG = False— never expose stack traces.- Keep
SECRET_KEYin an environment variable, never in Git. - Set
ALLOWED_HOSTSexplicitly. SECURE_SSL_REDIRECT = TrueandSECURE_HSTS_SECONDS = 31536000.SESSION_COOKIE_SECURE = TrueandCSRF_COOKIE_SECURE = True.
Habits
- Never build SQL with string formatting. Use the ORM or query parameters.
- Escape output. Avoid
|safeandmark_safeon user input. - Validate uploads — check size and type, and never serve them from the app domain without care.
- Rate-limit login and forms (e.g.
django-axesor DRF throttling). - Keep dependencies updated —
pip list --outdatedand GitHub Dependabot.
Admin
Move the admin from /admin/ to a non-obvious URL, enforce strong passwords and consider 2FA with django-otp.
Security is not a one-time task, but these ten points close the doors most attackers try first.