I will perform API security testing
Cybersecurity Specialist
About this Gig
I will perform an authorized API security assessment focused on authentication, authorization, input validation, access control, information exposure, and common API security risks.
Testing may include:
- API endpoint discovery and review
- Authentication testing
- Authorization and access-control testing
- IDOR/BOLA assessment
- Input validation testing
- Rate-limit/security-control review
- Sensitive information exposure checks
- API configuration review
- OWASP API Security risks
- Vulnerability validation
- Risk severity classification
- Professional security report
provide professional API security assessments to identify authentication, authorization, IDOR/BOLA, input-validation, rate-limit, information-exposure, and configuration vulnerabilities. Testing follows OWASP API Security practices, with validated findings, risk severity classification, and a clear professional security report.
Testing application:
Software
Device:
PC
•
Mac
•
Linux
•
Android mobile phone
•
Windows phone
My Portfolio
FAQ
Do you test websites without authorization?
No. All security testing is performed only on websites that you own or are explicitly authorized to have tested.
Do you provide a security report?
Yes. Depending on the selected package, you will receive a professional report containing findings, risk severity, evidence or proof of concept where appropriate, and remediation recommendations.
Can you test WordPress websites?
Yes. I can assess WordPress websites for common security weaknesses, configuration issues, outdated components, and other security risks.
Can you test APIs?
Yes. I can perform authorized API security assessments, including authentication, authorization, access control, input validation, and common API security risks.
Do you perform manual security testing?
Yes. Standard and Premium packages can include manual testing in addition to appropriate automated security checks.
Do you test the OWASP Top 10?
Yes. OWASP Top 10 risks can be assessed as part of the appropriate security testing package.
Will you provide recommendations to fix vulnerabilities?
Yes. The report can include practical remediation recommendations to help you understand and address identified security issues.
Can you test a production website?
Yes, provided you have authorization and the required testing scope is clearly defined. Testing can be adjusted to minimize potential service disruption.
Do I need to provide login credentials?
Only when authenticated testing is required. You should provide test credentials when necessary rather than personal or unnecessary account information.
Can you retest after vulnerabilities are fixed?
Yes. Retesting can be discussed as an additional service or included where specified in the selected package.

