I will test your web application for security vulnerabilities and owasp report


About this gig
Worried your web app has security weaknesses someone could find before you do? I'll run a thorough, authorized web application security assessment and give you a clear, professional report you can act on.
I will security-test YOUR OWN web app (with your permission) and assess:
- Authentication, authorization and access control
- Session handling, cookies and security headers
- Input validation and injection (SQLi, XSS and more)
- Security misconfiguration and sensitive-data exposure
- API security: endpoints, auth and rate limiting
- OWASP Top 10 coverage, severity-rated
WHY ME:
- Cloud-native security engineer, 5+ public security platforms built
- CS thesis on adaptive intrusion detection (IEEE manuscript)
- Findings mapped to OWASP Top 10 with practical fixes
TOOLS:
OWASP Top 10, OWASP ASVS, Burp Suite, OWASP ZAP, Nmap, Nikto and manual testing
SUPPORTED: WordPress, PHP/Laravel, Node.js, React, Django/Flask, REST APIs.
YOU GET:
- Professional PDF report: executive summary and findings
- Severity ratings, evidence and business impact
- Step-by-step fixes and free retest (Standard and Premium)
Message me BEFORE ordering with your app URL and scope. Authorized testing only.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Suliman Khan
Cloud Native Security and DevSecOps Engineer, Kubernetes CI CD AI Safety
- FromPakistan
- Member sinceAug 2025
- Avg. response time1 hour
Languages
English
My Portfolio
FAQ
Q: What do you need from me to get started?
Your application URL, the scope (which parts to assess), written confirmation that you're authorized to have it tested, and test logins if the app requires an account. If API testing is included, share your API docs. I confirm everything with you in chat before I begin.
Do I need to own the application?
You need to either own it or have explicit written permission from the owner. I only perform authorized, defensive testing — I'll ask you to confirm this before any work starts. I can't test a site you're not authorized to test.
Do you provide a report?
es — every order includes a professional PDF security assessment report: findings, severity ratings, evidence, business impact and step-by-step remediation. Standard and Premium also include an executive summary for non-technical stakeholders.
Can you test APIs?
Yes. REST/GraphQL API security testing is included in Premium, and available as an add-on for Basic and Standard. Share your Swagger/OpenAPI or Postman collection and I'll assess endpoint auth, access control, rate limiting and common API risks.

