I will do wordpress penetration testing and security vulnerability audit


About this gig
Hi, I'm Shoriful, a cybersecurity specialist. I will perform a professional WordPress penetration test and security vulnerability audit to identify security weaknesses before the data breach.
WHAT I TEST (Manual + Automated):
- WordPress core, plugins & themes for known CVEs and zero-day risks
- SQL Injection, XSS, CSRF, RCE, Authentication & Privilege Escalation
- File permissions, directory listing & configuration weaknesses
- Malware, backdoors & suspicious code indicators
- User enumeration, weak passwords & brute-force exposure
- Database security, SSL/TLS issues & missing security headers
- OWASP Top 10 vulnerabilities specific to WordPress
WHAT YOU RECEIVE:
- Professional PDF security report
- Risk-rated findings (Critical / High / Medium / Low)
- Clear proof of every vulnerability found
- Step-by-step remediation guide (easy for non-technical owners)
- Plugin & theme update recommendations
- Security hardening checklist
TOOLS & METHODOLOGY:
- WPScan | Burp Suite | Nmap | Nuclei | Manual code review | OWASP methodology
WHY CHOOSE THIS SERVICE:
- 100% ethical & confidential
- Manual and automated security testing
- Fast delivery
- Report and Remediation
- Evidence of identified issues
- 30 days free support
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Shoriful Raj
Web Application Penetration Tester, OSINT and Wordpress Expert
- FromBangladesh
- Member sinceMay 2026
- Avg. response time3 hours
Languages
Bengali, English, Hindi
My Portfolio
Other Website Maintenance Services I Offer
FAQ
Will you hack or damage my website?
No. This is fully authorized, ethical penetration testing only. I identify vulnerabilities so you can fix them — I do not exploit or harm your site. All testing is non-destructive and legal.
Do you need login access to my WordPress site?
For Basic package: Only the website URL is required. For deeper testing (Standard & Premium): A temporary admin or test account is preferred for more accurate results. I will never change anything without your permission.
Will you also fix the vulnerabilities you find?
Basic package includes a detailed report with clear fix instructions. Standard and Premium packages include remediation guidance, and Premium can include hands-on security hardening (depending on the package you choose). Message me if you want fixes included. 4. Is the testing safe for my live web
Is the testing safe for my live website?
Yes. I use non-destructive methods that will not slow down or break your site. If you prefer, testing can also be done on a staging/copy of your website.
What exactly will I receive?
You will receive a professional PDF security report that includes: All discovered vulnerabilities with risk ratings (Critical / High / Medium / Low)
How long does the security audit take?
Delivery time depends on the package: Basic: 1–2 days Standard: 2–3 days Premium: 3–5 days
What if my website is already hacked or has malware?
This gig is focused on vulnerability assessment and penetration testing. If your site is already compromised, please message me first — I can advise or offer a separate malware removal service.
Is my website data kept confidential?
Yes. All information is 100% confidential. An NDA can be signed upon request before testing begins.
Do you test only WordPress websites?
Yes, this gig is specialized for WordPress sites (including WooCommerce). For other platforms, please message me first.
Should I message you before placing an order?
Yes, please. Share your website URL so I can confirm the scope, recommend the right package, and give you an accurate delivery time.

