I will do a web application security audit and find vulnerabilities for you


About this gig
Is your website truly secure? Most businesses assume yes until they get hacked.
I am a B.Tech CSE Cybersecurity graduate and active bug bounty hunter on BugCrowd with hands-on VAPT experience.
What I test for:
SQL Injection (SQLi)
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Broken Authentication
Sensitive Data Exposure
Security Misconfiguration
Broken Access Control (IDOR)
OWASP Top 10 full coverage
Tools I use:
Burp Suite
OWASP ZAP
Nmap
Metasploit
Wireshark
What you receive:
Professional PDF security report
Severity rating per finding (Critical/High/Medium/Low)
Fix recommendations in plain English
Executive summary for non-technical stakeholders
Who this is for:
Developers securing apps before launch
Startups handling customer data
Small businesses with an online presence
️ I only test sites you own or have written permission to test. Message me before ordering to confirm scope.Is this legal? Will you access my site without permission?
Get to know Sajal
Penetration Tester
- FromIndia
- Member sinceAug 2026
- Avg. response time1 hour
Languages
Bengali, English, Hindi
Other Software Development Services I Offer
FAQ
Is this legal? Will you access my site without permission?
I only perform security testing on websites and applications you own or have explicit written permission to test. All work follows ethical hacking standards and I will ask you to confirm ownership before starting any testing.
What do I need to share to get started?
Just the URL of your website or web app and confirmation that you own it or have testing permission. A staging or test environment is preferred for deeper testing so your live users are not affected during the audit.
What format is the security report in?
You receive a professional PDF report with an executive summary, complete list of vulnerabilities found, CVSS severity ratings (Critical / High / Medium / Low), and clear remediation steps written in plain English — no confusing jargon.
Will the audit affect my live website or its users?
I use non-destructive, passive testing methods that do not delete data, take systems offline, or interrupt normal operations. For complete peace of mind I recommend providing a staging environment wherever possible.

