I will perform a web application penetration test based on owasp
Information Security Specialist
About this Gig
I'm an offensive security consultant with 5+ years in penetration testing (eCPPT, eJPT, MCRTA, C-AI/ML Pentester). I test your web application following the OWASP Web Security Testing Guide (WSTG) v4.2 reconnaissance, configuration, authentication & session management, input validation (SQL injection, XSS, and more), API authorization, and access control.
Every finding is manually verified before it reaches your report. You get a clear report with business-impact analysis, reproduction steps, and prioritized remediation your engineering team can act on immediately.
Testing runs through a custom automation pipeline I built myself, combined with hands-on manual exploitation and validation for every vulnerability.
Ideal for: SaaS platforms, e-commerce, internal business tools, and APIs before a compliance audit, security review, or production launch.
️ I only test systems you own or are explicitly authorized to test. I'll ask for written scope (domains, IPs, and a testing window) before starting. No unauthorized access ever.
Message me before ordering so I can confirm scope and recommend the right package.
FAQ
Will you test a system I don't own?
No. I only test assets you own or are explicitly authorized to test. I require written scope and authorization before any testing begins.
What do you need from me to start?
Target domain(s)/app URL, the type of test (black-box or gray-box), user credentials if applicable, and your authorized testing window.
Can you retest after we fix the issues?
Yes — included in the Premium package, or available as an add-on.
Is my data confidential?
Absolutely. All findings are reported privately and directly to you. Sample reports in my gallery are fully anonymized.

