Harden code against vulnerabilities: OWASP prevention, input validation, authentication, data storage, and third-party safety. Do NOT use for mechanical a11y fixes.