I will do penetration testing and vulnerability assessment of your website


About this gig
Is your website secure, or does it just look secure?
I run professional penetration testing and vulnerability assessments on websites, web apps, APIs, Linux servers and databases you own or are authorized to test. You get a clear, actionable report, not just a scanner printout.
What I test for:
- OWASP Top 10 (SQLi, XSS, CSRF, file upload flaws & more)
- Authentication, session handling & access control
- Business logic flaws scanners miss
- Linux & system security
- Database security
- Misconfigurations & outdated components
- Exposed files, directories & endpoints
- SSL/TLS and security headers
- API endpoints (add-on)
Every finding includes a description, steps to reproduce it, a severity rating, and the exact fix, written so your developer can act on it right away.
Written authorization from the site owner is required before testing begins. Non negotiable.
Why choose me:
- Manual security testing, not just automated scans
- Every vulnerability verified, no false positives
- Clear, developer-ready reports with fix guidance
- 30 days free support after delivery
Contact me before ordering to discuss your project.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Mahamudul Hasan
Cybersecurity Specialist and Secure Web Development Expert
- FromBangladesh
- Member sinceAug 2026
- Avg. response time5 hours
Languages
Bengali, English
My Portfolio
Other Website Maintenance Services I Offer
FAQ
What is penetration testing?
A controlled security test. I try to find the weaknesses in your site the way an attacker would, then hand you the list with instructions to fix them instead of exploiting them.
How is this different from a vulnerability scan?
A scan is automated and finds known issues. A pentest adds manual, hands-on testing — the only way to catch broken access control, privilege escalation and business logic flaws.
Do you need permission to test my site?
Yes, always, in writing. I test targets you own or are formally authorized to test, and nothing else.
Will testing break my site or slow it down?
Testing is non-destructive and the window is agreed with you first. I avoid load-heavy techniques on production and stop immediately if anything looks unstable.
Can you test a staging site instead of production?
Yes, and I'd prefer it when staging is a real copy. Just tell me if the two differ meaningfully.
What does the report look like?
Each finding gets a description, reproduction steps, evidence, a severity rating and a concrete fix. Premium also includes a plain-English summary for non-technical readers.
Do you fix the vulnerabilities too?
This gig covers finding and reporting them. If you want implementation of fixes, I'll quote that separately as development work.
Do you test Linux servers and databases?
Yes, as an add-on — I'll need SSH or database access with an agreed scope before starting.
Can you help with compliance requirements?
The report supports work toward SOC 2, PCI and similar, and I can provide an attestation letter. I'm not a certifying auditor, so your auditor has final say.
Will you sign an NDA?
Yes. Send it before the order starts. Your findings stay confidential either way, and I don't reuse client data.

