I will do a professional security audit of your website or rest API

V
vl4dimirz
V
vl4dimirz
Phisit T

About this gig

Most web apps ship with the same security holes: broken access control, weak authentication, exposed config files, and missing hardening. Attackers look for exactly these. I find them first and give you a clear, prioritized plan to fix them.


I build production backends myself (FastAPI, Next.js, auth, payments), so I audit like an engineer, not a scanner - real findings with proof, not a wall of false positives.


What I check:

- Access control (IDOR / BOLA) - the #1 API risk

- Authentication, sessions, and tokens

- Injection and input-validation surface

- SSRF, CORS, open redirects

- Security headers, TLS, exposed files


What you get:

- A professional report: severity, proof-of-concept, and exact fix steps

- Findings mapped to the OWASP Top 10 / API Top 10

- Straight answers on what actually matters, not scare tactics


My testing is non-destructive and read-only: no data theft, no downtime. I only test systems you own or are authorized to test, and you confirm that before I start. Everything stays confidential.


Message me with your target and scope before you order so I can confirm the right package.

Respect third-party rights

Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.

Get to know Phisit T

Phisit T

FullStack Developer

  • FromThailand
  • Member sinceJun 2026
  • Languages

    English
I am a full-stack developer specializing in building production-ready web apps and MVPs using Next.js, TypeScript, and PostgreSQL. With a background in sales, I focus on scoping projects around real business goals and delivering fast, clean, and responsive solutions including payment systems and AI integrations.

My Portfolio