I will do android security testing and mobile pentest
Security Researcher and Web App Pentester
About this Gig
Launching an Android app or preparing for Google Play review? A single exposed API key, weak permission, or insecure data storage can lead to store rejection, data breaches, and ruined trust.
I deliver enterprise-grade, OWASP MASVS-aligned Mobile Application Security Testing and APK Penetration Testingagency-quality audits without the $1,500+ price tag.
WHY CHOOSE THIS AUDIT?
Deep Static Code Analysis: Decompiling APK/AAB files to uncover exposed keys, weak encryption, and AndroidManifest flaws.
Dynamic Runtime Testing: Live HTTP/HTTPS traffic interception, SSL Pinning checks, and local database storage leak inspection.
Zero False Positives: Every vulnerability is manually cross-verified for high technical accuracy.
Developer-Friendly Remediation: Clear fix instructions with PoC proof, not raw scanner dumps.
WHAT YOU GET IN YOUR PDF REPORT:
1. Executive Summary with CVSS 3.1 Severity Matrix
2. OWASP Mobile Top 10 Audit Breakdown
3. Step-by-Step Fix Instructions for your Dev Team
4. Google Play Policy Security Readiness
Securing Flutter, React Native, Java, and Kotlin APKs.
Protect your app before launch! Order now or message me for a quick consultation.
Testing application:
Mobile app
Development technology:
Flutter
•
Java
•
Kotlin
•
Python
•
React Native
Device:
PC
•
Linux
•
Android mobile phone
•
Android tablet
My Portfolio
FAQ
Will your security testing break or disrupt my live app or database?
No. All static and dynamic tests are conducted non-destructively in secure, isolated sandbox environments. Your live production servers, APIs, and user data remain 100% safe and untouched.
Will this report help my app get approved on the Google Play Store?
Yes! The audit checks for Google Play security compliance issues, including unauthorized data collection, insecure permission configurations, and unencrypted network traffic required for store approval.
What files do I need to provide to start the security audit?
You only need to provide your .apk or .aab file (or a download link like Google Drive). If your app requires a user login to access internal screens, providing demo credentials allows for full dynamic testing.
How is this different from running a free automated security scanner?
Automated scanners generate noisy, false-positive-heavy reports without context. I perform multi-engine code analysis, live dynamic traffic interception, and manual verification to give you actionable fixes.
Do you support cross-platform apps built with Flutter or React Native?
Yes! I audit native Android applications (Java and Kotlin) as well as cross-platform frameworks (Flutter, React Native) and hybrid WebView applications.
What if my developer needs help fixing a reported vulnerability?
Every vulnerability in the PDF report includes clear, developer-oriented remediation guidance and proof-of-concept evidence. You can also select the Premium tier or add a Re-Test extra for follow-up verification.

