Technology has been progressively making a substantial positive influence on social life. If we see the development of past ten years it has made a big hop. The internet and Web application is growing fast in the world. The reason behind this the costs of bandwidth are knowingly getting poorer and enlargements of new emerging technologies are constantly mounting over the years, the facilities are widely accessible around the world and so is the use of Internet amenities. Currently, web appliances are playing a noteworthy role towards creating an individual’s life informal. They are making a decent occurrence in the regions such as education, banking, entertainment, social media, online transaction, and gaming and many more. Only being competent and cost effective in not satisfactory. These appliances should be protected and consistent too. Over the ancient period, along with the enlargement of web skills, new attacking methods are also evolving with numerous types of dangerous vulnerabilities like SQL injection, XSS, CSRF and many more. To figure out those vulnerabilities from an application there are so many tools for testing application. The objective of this thesis to find different security tools with their effectiveness. Also find the preventive methods against those attacks and to search common types of susceptibilities and finally make user awareness of security information.