I will perform a secure code review and find security vulnerabilities
About this Gig
I will perform a security-focused source code review to identify vulnerabilities and insecure coding practices before they become real security issues.
I review application code manually and, where appropriate, use security-focused analysis tools to identify issues such as:
- SQL injection and other injection risks
- XSS and unsafe input handling
- Authentication and authorization weaknesses
- IDOR/BOLA risks
- Hardcoded credentials and secrets
- Sensitive data exposure
- Insecure cryptography
- File handling vulnerabilities
- SSRF and command injection risks
- Security misconfigurations
- Unsafe dependency usage
- Business-logic security issues where identifiable from code
You will receive:
- Vulnerability description
- Severity and impact
- CWE/OWASP mapping where applicable
- Affected file/function/line
- Evidence or code references
- Practical remediation recommendations
I only review code that you own or are explicitly authorized to have assessed.
For large repositories, multiple applications, or complex codebases, please contact me before ordering so I can confirm the scope and provide an appropriate offer.
Development technology:
C/C++
My Portfolio
FAQ
What type of code can you review?
I can review web applications, APIs, backend services and other application code where the security of the implementation can be assessed from the source code. Please provide the programming language and framework before ordering.
Do you perform penetration testing with this Gig?
No. This Gig is primarily a source-code security review. Dynamic testing and penetration testing can be scoped separately when required.
Do I need to provide the entire source code?
No. You can provide the relevant repository, modules or files within the agreed scope. The amount of code included depends on the selected package.
Can you review private GitHub/GitLab repositories?
Yes, provided you have authorization to share the code and the access method complies with Fiverr's requirements.
Will you identify every vulnerability?
No security review can guarantee that every vulnerability will be discovered. The review identifies security issues that can reasonably be found within the agreed scope and available code.
Will you provide remediation recommendations?
Yes. Findings include practical remediation recommendations appropriate to the identified issue.
Can you review authentication and authorization logic?
Yes, when the relevant source code and application flow are included in the review scope.
Can you review a large codebase?
Yes. Large repositories should be discussed before ordering so the scope, code volume, timeline and price can be agreed upon.

