
OWASP Security Testing & Vulnerability Assessment
Delivery in
5 days
- Views 15
Amount of days required to complete work for this Offer as set by the freelancer.
Rating of the Offer as calculated from other buyers' reviews.
Average time for the freelancer to first reply on the workstream after purchase or contact on this Offer.
What you get with this Offer
I will conduct an OWASP Top 10-based security vulnerability assessment of your web application — covering SQL injection, Cross-Site Scripting (XSS), broken authentication, sensitive data exposure, XML External Entity injection, broken access control, security misconfiguration, insecure deserialization, known vulnerable dependencies, and insufficient logging — using a combination of automated scanning (OWASP ZAP, Burp Suite Community) and manual verification, and delivering a security assessment report with findings, CVSS severity scores, and remediation guidance. Security testing conducted only with automated scanners produces high false positive rates and misses the business logic vulnerabilities, broken access control issues, and authentication bypass paths that require manual verification to identify; this service combines both approaches.
The assessment covers automated scanning with OWASP ZAP, manual verification of scanner findings, manual testing for authentication and session management weaknesses, authorisation testing (IDOR and privilege escalation), input validation and injection testing, sensitive data exposure in API responses and error messages, and a security assessment report with CVSS score, severity rating, reproduction steps, and specific remediation recommendations for every confirmed finding.
Designed for development teams preparing for a security review, organisations handling personal or financial data, and businesses seeking Cyber Essentials or ISO 27001 certification who need a web application security assessment conducted by a qualified tester.
The assessment covers automated scanning with OWASP ZAP, manual verification of scanner findings, manual testing for authentication and session management weaknesses, authorisation testing (IDOR and privilege escalation), input validation and injection testing, sensitive data exposure in API responses and error messages, and a security assessment report with CVSS score, severity rating, reproduction steps, and specific remediation recommendations for every confirmed finding.
Designed for development teams preparing for a security review, organisations handling personal or financial data, and businesses seeking Cyber Essentials or ISO 27001 certification who need a web application security assessment conducted by a qualified tester.
What the Freelancer needs to start the work
Please provide a staging or dedicated test environment URL (never production for active security testing), test account credentials for each user role, your application's primary functionality overview, written authorisation confirming you own or are authorised to test the application, and any specific security concerns or recent incidents to prioritise.
We collect cookies to enable the proper functioning and security of our website, and to enhance your experience. By clicking on 'Accept All Cookies', you consent to the use of these cookies. You can change your 'Cookies Settings' at any time. For more information, please read ourCookie Policy
Cookie Settings
Accept All Cookies