I will do a manual web app and API penetration test with detailed report
Web App and API Penetration Tester with Published CVEs
About this Gig
Most pentests you buy online are just a scanner run and a messy PDF. That won't pass a
SOC 2 audit or a vendor security review, and it won't stop a real attacker. I do it the
other way around: manual, hands-on testing, and I've got the public CVEs to back it up.
Quick proof, since talk is cheap. I've published security advisories and a CVE in real
auth frameworks like better-auth and n8n, plus validated findings on Twilio, SAP, and
FusionAuth. So I go after the bugs scanners miss: auth and OAuth bypasses, broken access
control, business-logic flaws, and API abuse.
What you get: a report you can actually read, a working proof-of-concept for every
finding, fixes your devs can act on, and a free re-test after you patch.
Not sure which package fits? Message me with your app or API and what you're worried
about, and I'll tell you straight.
My Portfolio
FAQ
Is this a real manual test or just an automated scan?
Manual. I use tools for recon, but the actual testing and every finding is hands-on. That's the whole point, it's what catches the bugs scanners walk past.
Will this help with my SOC 2 / vendor security review?
Yes. You get a clean, severity-rated report with proof and fixes that you can hand to an auditor or a client.
My app isn't built yet / it's small. Worth it?
Start with Basic. I'll check the highest-risk parts and tell you what matters most.

