I will do a professional security audit of your website or rest API


About this gig
Most web apps ship with the same security holes: broken access control, weak authentication, exposed config files, and missing hardening. Attackers look for exactly these. I find them first and give you a clear, prioritized plan to fix them.
I build production backends myself (FastAPI, Next.js, auth, payments), so I audit like an engineer, not a scanner - real findings with proof, not a wall of false positives.
What I check:
- Access control (IDOR / BOLA) - the #1 API risk
- Authentication, sessions, and tokens
- Injection and input-validation surface
- SSRF, CORS, open redirects
- Security headers, TLS, exposed files
What you get:
- A professional report: severity, proof-of-concept, and exact fix steps
- Findings mapped to the OWASP Top 10 / API Top 10
- Straight answers on what actually matters, not scare tactics
My testing is non-destructive and read-only: no data theft, no downtime. I only test systems you own or are authorized to test, and you confirm that before I start. Everything stays confidential.
Message me with your target and scope before you order so I can confirm the right package.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Phisit T
FullStack Developer
- FromThailand
- Member sinceJun 2026
Languages
English
My Portfolio
FAQ
Q: Is this legal and safe?
A: Yes. I only test systems you own or are authorized to test, and testing is read-only and non-destructive - no data is changed or removed, and there is no downtime. You confirm authorization before I begin.
Q: Will this take my site down?
A: No. All testing is passive and read-only. I do not run denial-of-service, brute-force, or destructive attacks.
Q: I'm not technical - will I understand the report?
A: Yes. Every report has a plain-language summary of what matters and why, plus a technical section your developer can act on directly.
Q: Can you also fix the issues you find?
A: Yes - I'm a full-stack developer. Add the "Security patch installation" extra, or we can scope the fixes as a separate order.
Q: What do you need from me to start?
A: Your target URL(s), the scope, written confirmation you're authorized to have it tested, and test credentials if authenticated areas are included.

