I will do website and web application penetration testing and vulnerability assessment


About this gig
I help businesses find and fix security vulnerabilities in their websites and web applications before attackers do through structured, OWASP Top 10-aligned penetration testing.
WHAT YOU GET
- Manual + automated testing of your website/web app against the OWASP Top 10
- A clear, prioritized report: Critical / High / Medium / Low severity
- Practical remediation steps for every finding (not just a vulnerability dump)
- A short call to walk through the results if you need it
WHY WORK WITH ME
I hold dual EC-Council CEH v13-aligned certifications (Advanced Red Teaming Practitioner + SOC Analyst Operations) and built SentinelScan, a live OWASP Top 10 / MITRE ATT&CK-aligned scanning platform I engineered end-to-end. I also completed a full authorized external penetration test on a live production domain (banoqabil.pk) with a formal PDF remediation report; this isn't theoretical- it's applied.
WHAT'S NOT INCLUDED: Physical security testing, social engineering/phishing simulations, DDoS testing, and production network infrastructure pentesting are outside the scope for this gig message me if you need a custom quote for those.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Daniyal Rashid
Web App Penetration Tester, OWASP Top 10, Vulnerability Assessment, CEH v13
- FromPakistan
- Member sinceAug 2026
Languages
English
My Portfolio
FAQ
Do you need login access to my site?
Only for authenticated testing in the Standard/Premium package (e.g., testing behind a login). Basic scans don't require credentials.
Will testing cause downtime or break anything?
I test carefully to avoid disruption, but any live security testing carries a small inherent risk. I recommend testing on staging where possible, and I'll flag anything destructive before running it.
Do I need to give you written authorization?
Yes, you must confirm that you own the domain or have explicit written permission to have it tested. This is required before I start any work (to protect both of us).
What's actually in the report?
Every vulnerability found, its severity (Critical/High/Medium/Low), how it could be exploited, and specific steps to fix it, not just a raw scanner output.
Can you test a staging environment instead of production?
Yes, and it's usually the safer option to send the staging URL in your order requirements.
What if my site is behind a firewall/WAF that blocks scanning?
Let me know the requirements, and I'll send you IPs to whitelist so the scan isn't blocked.

