I will perform professional API penetration testing and security assessment


About this gig
Professional API Penetration Testing & Security Assessment!
Is your REST or GraphQL API secure against real-world attacks? I provide manual API penetration testing based on the OWASP API Security Top 10 to find vulnerabilities before attackers do.
Services Include:
- Authentication & Authorization Testing
- BOLA (IDOR) Detection
- Broken Authentication
- JWT Security Review
- Rate Limiting & Mass Assignment
- SQL/NoSQL Injection
- SSRF & File Upload Testing
- Input Validation Flaws
- Security Misconfiguration
- Sensitive Data Exposure
- Business Logic Testing
- API Enumeration
- GraphQL Security Assessment
You'll Receive:
- Professional PDF Report
- Executive Summary
- Risk Rating (Critical/High/Medium/Low)
- Proof of Concept & Screenshots
- Technical Findings
- Remediation Recommendations
Tools:
Burp Suite, Postman, OWASP ZAP, Nmap, ffuf, curl, Nuclei, jwt_tool, HTTPie, custom Python scripts.
Supported APIs:
REST, GraphQL, JSON API, Mobile App APIs, SaaS APIs, Internal & Public APIs.
I combine manual testing with proven tools for accurate results, low false positives, and practical fixes. Contact me first for multi-API or authenticated testing projects.
If you have any queries, feel free to ask me!
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Faisal Mahmud
CyberSecurity Specialist, Penetration Tester, Vulnerability Researcher!
- FromBangladesh
- Member sinceOct 2025
- Avg. response time1 hour
Languages
Bengali, English, Urdu
My Portfolio
FAQ
Will testing affect my live production environment?
No active exploitation or destructive testing is performed on production without prior agreement. I recommend testing in a staging environment when possible. If production testing is required, we'll define safe boundaries (rate limits, excluded endpoints) before starting.
Do you need API documentation or credentials to start?
Yes — for authenticated testing, I'll need API documentation (Swagger/Postman collection), test credentials with different role levels (admin, user, guest), and a signed authorization letter confirming you own or have permission to test the target.
How long does a full assessment take?
Typically 3–7 days, depending on the number of endpoints, authentication complexity, and whether it's REST, GraphQL, or both. Larger or multi-API projects may take longer — I'll confirm the timeline after reviewing your API scope.
What if you find a critical vulnerability during testing?
I immediately notify you outside the normal reporting timeline for any Critical- or High-severity finding (e.g., BOLA leading to full account takeover, RCE, or auth bypass) so you can patch it right away, rather than waiting for the final report.
Do you offer retesting after I fix the vulnerabilities?
Yes, one round of retesting is included to verify that identified vulnerabilities have been properly remediated. I'll issue an updated report confirming which findings are closed and which are still open.

