
Web Application Penetration Test
- or -
Post a project like this£500(approx. $660)
- Posted:
- Proposals: 36
- Remote
- #4457678
- OPPORTUNITY
- Expired
Data Science & Machine Learning Engineer | Web App developer | AI Application Development
Full-Stack Web & Mobile App Developer With AI Integration & Automation Expertise
Full Stack Web & Mobile App Developer | Expert in Android & iOS |Graphic Design| Video Editing & Animation|Certified & Top Rated

Experienced Full Stack Web (custom/WordPress) + AI developer + Dev-Ops | Top-rated
Top rated PHP Web Development |Hubspot Certified|Bubble.io | CMS and frameworks | Designing|Graphic Designing,|SEO

56231488014935118922281230859012903820128760721194336612844907118184564899784129879552868553
Description
Experience Level: Expert
Web Application Penetration Test (Budget-Conscious)
Project Overview
We are looking for a practical, no-nonsense penetration test of a web-based application. The goal is to identify obvious and material security weaknesses and provide clear, actionable fixes, not to produce an academic or compliance-heavy report.
This is a small, well-defined engagement suitable for an experienced freelancer.
Scope of Testing
In scope:
Public-facing web application
Login, authentication, and authorisation flows
Application APIs
Input validation and data handling
Out of scope:
Denial of Service (DoS) testing
Social engineering or phishing
Physical security
Third-party platforms or services
Testing Approach
Grey-box testing (limited information provided)
Combination of automated tools and manual testing
Focus on OWASP Top 10 style vulnerabilities
Emphasis on realistic attack paths, not theoretical issues
Deliverables
A concise written report including:
Short executive summary
List of vulnerabilities found
Severity rating (Critical / High / Medium / Low)
Evidence (screenshots or request/response samples)
Clear remediation steps
Length expectation: 10–15 pages max (brevity preferred).
Optional:
Re-test after fixes (separately priced)
Constraints & Rules
Testing during agreed time window
No intentional data deletion or service disruption
Any critical issue to be reported immediately
Do not retain or share any data after completion
Pricing Guidance
To keep proposals aligned:
Expected effort: 1–3 days testing + 1 day reporting
Target budget range: £500
Please explain clearly if your proposal exceeds this range
We are not seeking enterprise compliance certification or formal audit sign-off — just solid security coverage at sensible cost.
Project Overview
We are looking for a practical, no-nonsense penetration test of a web-based application. The goal is to identify obvious and material security weaknesses and provide clear, actionable fixes, not to produce an academic or compliance-heavy report.
This is a small, well-defined engagement suitable for an experienced freelancer.
Scope of Testing
In scope:
Public-facing web application
Login, authentication, and authorisation flows
Application APIs
Input validation and data handling
Out of scope:
Denial of Service (DoS) testing
Social engineering or phishing
Physical security
Third-party platforms or services
Testing Approach
Grey-box testing (limited information provided)
Combination of automated tools and manual testing
Focus on OWASP Top 10 style vulnerabilities
Emphasis on realistic attack paths, not theoretical issues
Deliverables
A concise written report including:
Short executive summary
List of vulnerabilities found
Severity rating (Critical / High / Medium / Low)
Evidence (screenshots or request/response samples)
Clear remediation steps
Length expectation: 10–15 pages max (brevity preferred).
Optional:
Re-test after fixes (separately priced)
Constraints & Rules
Testing during agreed time window
No intentional data deletion or service disruption
Any critical issue to be reported immediately
Do not retain or share any data after completion
Pricing Guidance
To keep proposals aligned:
Expected effort: 1–3 days testing + 1 day reporting
Target budget range: £500
Please explain clearly if your proposal exceeds this range
We are not seeking enterprise compliance certification or formal audit sign-off — just solid security coverage at sensible cost.
Anthony S.
100% (14)Projects Completed
11
Freelancers worked with
10
Projects awarded
37%
Last project
23 Jan 2025
United Kingdom
New Proposal
Login to your account and send a proposal now to get this project.
Log inClarification Board Ask a Question
-
There are no clarification messages.
We collect cookies to enable the proper functioning and security of our website, and to enhance your experience. By clicking on 'Accept All Cookies', you consent to the use of these cookies. You can change your 'Cookies Settings' at any time. For more information, please read ourCookie Policy
Cookie Settings
Accept All Cookies