I will perform a web application security audit and penetration test
Full Stack Developer Firebase React Expert Security Researcher
About this Gig
Your web app might be leaking data right now without you knowing.
I'm a security researcher with hands-on experience in penetration
testing, vulnerability assessment, and real-world bug bounty hunting.
I've found real vulnerabilities in production applications including
exposed API keys, CORS misconfigurations, and authentication bypasses.
WHAT I TEST:
- OWASP Top 10 vulnerabilities
- SQL Injection / XSS / CSRF
- Authentication and session management
- API security and exposed endpoints
- CORS misconfiguration
- Sensitive data exposure
- Security headers analysis
- Firebase / cloud misconfiguration
- Broken access control
TOOLS I USE:
- Burp Suite
- OWASP ZAP
- Nuclei
- ffuf
- Nmap
- Custom scripts
YOU'LL RECEIVE:
- Detailed PDF report
- Severity rating for each finding (Critical/High/Medium/Low)
- Exact steps to reproduce each vulnerability
- Remediation recommendations
- Executive summary
️ IMPORTANT:
I only test applications you own or have explicit
written permission to test. Proof of ownership required.
Message me before ordering with your app URL and scope.
Testing application:
Web application
Device:
Linux
My Portfolio
FAQ
Will you test apps I don't own?
No. Proof of ownership or written permission required — no exceptions.
What format is the report in?
Professional PDF with clear sections, screenshots, and remediation steps.
Do you test mobile apps?
Currently web applications only. Message me for specifics.
Can you help fix the vulnerabilities you find?
Yes — upgrade to Premium or order a separate gig.
Is my app information kept confidential?
Yes, absolutely. I treat all client data as strictly confidential.
