I will perform a web application security penetration test


About this gig
Are you worried your website or web app has security vulnerabilities you don't know about? I perform manual and tool-assisted penetration testing to find real, exploitable weaknesses before attackers do not just an automated scan dump.
What I check:
- OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, broken auth, etc.)
- Authentication & session management flaws
- API security issues
- Input validation & injection points
- Misconfigurations and information disclosure
What you get:
- A clear PDF report: vulnerability found, risk level (Critical/High/Medium/Low), proof of concept, and remediation steps
- No jargon-only reports written so both developers and non-technical stakeholders understand the risk
- Confidentiality guaranteed (NDA available on request)
Why me: Completed Hack The Box's Web Penetration Tester path and Completing the General Penetration Tester Path, hands-on offensive security background, currently working as a cybersecurity TA.
Message me before ordering if your target has WAF/auth walls so I can scope it properly.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Deghidy
Cyber Security Engineer
- FromEgypt
- Member sinceSep 2024
Languages
English, Arabic, German
My Portfolio
FAQ
Do you need access to my site?
No admin access needed for most tests — I test from the outside like a real attacker would. If you want deeper testing (like checking logged-in areas), I may ask for a test account with limited permissions.
What if you find nothing?
You'll still get a full report confirming what was tested and that no vulnerabilities were found in that scope — useful for compliance, peace of mind, or showing clients/investors your app was audited.
Is this legal/safe for my live site?
Yes, as long as you own the site or have written authorization to test it (I'll ask you to confirm this before starting). Testing is done carefully to avoid disruption, but for high-traffic production sites, I recommend testing on a staging environment if one is available.

