I will perform web and API penetration testing and vulnerability assessment
About this Gig
Are you looking to secure your web application or API before launch? Do you need a professional penetration test to ensure your business and customer data remain safe from hackers?
I am an OSCP+ and CRTP certified Application Security Engineer with 5+ years of professional experience in offensive security, penetration testing, and vulnerability management. I help businesses identify critical security flaws before malicious actors can exploit them.
What I Will Test For:
- OWASP Top 10 Vulnerabilities (SQL Injection, XSS, CSRF, IDOR, SSRF, Broken Authentication)
- API Security Weaknesses (BOLA, Broken Authorization, Rate Limiting, Data Exposure)
- Business Logic & Privilege Escalation Flaws
- Insecure Server & Cloud Configurations
What You Will Receive:
- Detailed Technical Report: Clear breakdown of all identified vulnerabilities ranked by risk severity (Critical, High, Medium, Low).
- Proof-of-Concept (PoC): Step-by-step evidence and screenshots demonstrating how the flaw was identified.
- Developer-Friendly Remediation: Practical guidance on how to fix and patch each security gap effectively.
- Post-Fix Retesting: (Available in Premium) Verification to ensure patches were properly imple
FAQ
What do you need from me to get started?
I will need the URL/target scope, test credentials (if authenticated testing is required), and written authorization to test your target.
Will the penetration test disrupt my live website or service?
No, standard testing methods are designed to be safe and non-disruptive. If high-impact tests are required, we can schedule them during off-peak hours or on a staging environment.
Do you offer re-testing after I fix the vulnerabilities?
Yes! Retesting is included in the Premium package and available as an add-on for Basic and Standard packages.

