I have a very poor opinion of OWASP
content, because the couple of areas I’ve paid any attention to have never been any better than mediocre, clearly written by amateurs long ago and largely unmaintained ever since, with
known errors and heavily misleading statements hanging around for over a decade on no or unsound justification, among many other problems obvious to any that actually know the field. (See
https://hn.algolia.com/?query=chrismorgan%20owasp&type=comme... for a few comments with somewhat more detail, but things have historically been just
so bad and so
obviously bad that I haven’t bothered enumerating more than the issue that has annoyed me the most.)
(Sigh. I see that as part of fixing a lot of the obvious unsuitability of https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Sc... some time in the past two years—and it is much better now, though there are still a few dodgy things about it in both content and presentation—they reintroduced the erroneous advice to entity-encode /, which was only finally removed two years ago. Feel free to try to get that fixed, anyone; for my part, I have no interest in trying to work with OWASP.)