I maintain my own guide of concise webdev tips that's mostly distill from and links to recommendations from OWASP, Mozilla and Google which you might find a good jumping-off point: https://www.checkbot.io/guide/