I will do API penetration testing and owasp API top 10 security audit


About this gig
Are your APIs exposing critical vulnerabilities? As a C|PENT certified penetration tester, I provide professional API security testing and OWASP vulnerability assessments to protect your web applications from real-world attacks.
What I Test:
- OWASP API Security Top 10 vulnerabilities
- Authentication and authorization flaws (Broken Object Level Authorization)
- Injection attacks (SQLi, NoSQLi, Command Injection)
- Excessive data exposure and improper asset management
- Rate limiting and business logic vulnerabilities
- BOLA, BFLA, and Mass Assignment issues
- JWT token weaknesses and insecure session handling
What You Get:
- Detailed vulnerability report with risk ratings (Critical/High/Medium/Low)
- Step-by-step reproduction steps for each finding
- Remediation recommendations and best practices
- Executive summary for non-technical stakeholders
Tools Used: Burp Suite Pro, OWASP ZAP, Postman, custom scripts.
I hold C|PENT (Certified Penetration Testing Professional) certification with 95.2% score and have tested APIs across fintech, healthcare, and e-commerce sectors.
Contact me to discuss your specific API security needs before ordering.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know WASEEM KHAN
OSCP, CEH Master, CPENT, Penetration Tester and Security Consultant
- FromPakistan
- Member sinceJan 2017
- Avg. response time1 hour
- Last delivery6 years
Languages
English, Urdu, Pashto
My Portfolio
FAQ
Do you need my API documentation or source code?
No source code is required. I need your API base URL, any available documentation (Swagger/Postman), and test credentials. The more context you provide, the more thorough the assessment will be.
What API types do you test?
I test REST, GraphQL, SOAP, and gRPC APIs. Coverage includes OWASP API Top 10: broken object authorization, authentication flaws, injection attacks, rate limiting bypass, mass assignment, and excessive data exposure.
Will testing affect my live API or users?
By default I use non-destructive methods. I recommend a staging environment. If live API testing is needed, we schedule it during off-peak hours with your explicit approval before any active testing begins.
What do I receive at the end?
A detailed PDF report with all vulnerabilities, CVSS severity scores, request/response examples as proof of concept, and clear remediation steps. An executive summary is included for non-technical stakeholders.

