Skip to content

Author

Sahar Adnan Alselwi

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Review Open access Aug 2026

Bridging Frontend Development and Security Through Client-Side Protection A Literature Review

Modern web applications increasingly shift application logic, user interaction, and security-relevant processes to the browser, making the frontend layer a critical component of web application security. This article presents a bounded analytical literature review of eighteen academic studies on client-side security, frontend development, JavaScript ecosystems, secure coding, and web application security. The corpus was retrieved primarily through Google Scholar searches conducted in November–December 2025, complemented by backward citation tracking. Studies were included when they addressed browser-executed or JavaScript-based security and examined frontend frameworks, client-side authentication and state management, dependency and supply-chain risk, runtime enforcement, secure development methodology, or AI-assisted secure coding. The evidence was synthesized using thematic analysis rather than treated as comprehensive coverage of the field. The synthesized patterns show that frontend frameworks provide meaningful but conditional protection when developers follow architectural conventions and avoid unsafe rendering or direct DOM manipulation. However, third-party and transitive dependencies expand the client-side attack surface, while insecure token storage, weak state management, and excessive trust in browser-executed logic remain persistent weaknesses. Runtime defenses can reduce the impact of malicious or compromised scripts, but adoption is constrained by performance, compatibility, configuration, and integration barriers. Large language models may support vulnerability explanation, secure code generation, and developer learning, but require human validation to mitigate correctness, contextual, and overreliance risks. Overall, client-side protection is identified as a socio-technical security problem requiring framework discipline, dependency governance, runtime monitoring, and accountable AI-assisted development.

Sahar Adnan Alselwi, Soemantri Soemantri · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.