The digital transformation of immigration services requires websites that are secure, reliable, and capable of protecting sensitive user data. At the same time, the increasing use of websites in public services amplifies the risk of exploiting application security vulnerabilities. This study aims to systematically analyse prior studies on website security testing using black box and white box approaches and to examine the tendency of their effectiveness in the context of immigration service websites. The method used is a Systematic Literature Review (SLR) following the PRISMA 2020 guideline. PRISMA 2020 provides a checklist and flow diagram for transparent systematic review reporting, while the OWASP Web Security Testing Guide (WSTG) serves as a comprehensive guideline for web application security testing. Literature sources were obtained from Garuda, Scopus, Google Scholar, and Semantic Scholar within the 2021-2026 publication period. Based on the identification, screening, and eligibility selection process, 30 articles were selected. The synthesis results show that the black box approach still dominates website security testing because it is more practical, faster, and suitable for simulating attacks from the external side. In contrast, white box provides greater analytical depth because it leverages knowledge of the internal structure of the application. The most dominant tools and references are OWASP ZAP, OWASP Top 10, and OWASP WSTG. This study concludes that for immigration service websites, black box is more effective for initial detection and evaluation from the attacker's perspective, whereas white box is more effective for in-depth verification and continuous improvement. Therefore, the combination of both approaches is the most recommended.
Copyrights © 2026