• Projects 30
  • Rating 5.0
  • Rating 5 747

Budget: 18000 UAH Deadline: 7 days

Good day.

We can conduct an audit of the web application before the release and prepare a report for the developer - with a description of risks, reproduction steps, priority for fixes, and recommendations for closing vulnerabilities.

Based on experience - we work with corporate systems, personal accounts, roles, payments, integrations, admin panels, and products where an error in access or logic can cost money and reputation. In security, it is important not only to check for typical vulnerabilities but also to assess the application logic - who can see, change, export, pay, delete, and bypass what.

Similar projects with a comparable level of responsibility:
> https://business.ingello.com/platforma - corporate platform with roles, processes, and complex logic
> https://business.ingello.com/forma-crm - CRM where access, client data, and process stability are crucial
> https://systems-fl.ingello.com - our profile in system development and technical expertise

Similar project: Рефаткоринг приложения
  • Projects -
  • Rating -
  • Rating 584

Budget: 13000 UAH Deadline: 4 days

Good day! I am ready to conduct a security technical audit of the application before release: checking against OWASP Top 10, basic SAST/DAST scan, and manual verification of critical points - authorization, API, forms, security headers. The result will be a structured report detailing vulnerabilities, risk levels, and recommendations for the developer. I have experience working with Linux/AWS infrastructure, so I will also consider the server-side configuration. I am ready to start immediately after receiving the link to the product.

  • Projects 34
  • Rating 5.0
  • Rating 2 173

Budget: 5500 UAH Deadline: 4 days

Good day, Pavlo! I was intrigued to review your task regarding the cybersecurity audit of the web application before its release. I understand the importance of thorough vulnerability checks and a quality report for developers to ensure the reliability of the product. My experience in this field will allow me to identify potential risks and provide clear recommendations for their mitigation.

My approach to the audit includes three main stages: first, I will conduct automated scanning to detect common vulnerabilities, then I will perform manual penetration testing, including checking business logic and possible attack vectors, and I will conclude with the development of a detailed report describing the identified issues, assessing their criticality, and providing specific recommendations for your developers. My responsibility, attention to detail, and punctuality guarantee that you will receive a complete and high-quality result within the established deadlines.

The cost of the work is 5500 hryvnias, and the completion time is 4 working days from the moment access to the application is provided. If needed, I am ready to provide links to case studies of similar projects in personal messages. Also, as a bonus for our collaboration, after completing the audit and addressing the identified vulnerabilities, I will conduct a follow-up express check of the most critical areas at no additional charge to confirm the effectiveness of the changes made.

Are there any specific features in the structure of your web application or the technologies used that should be considered when planning the audit?

  • Projects -
  • Rating -
  • Rating 196

Budget: 24000 UAH Deadline: 5 days

We already have a nearly ready process for auditing web applications before release - we can quickly adapt it to your product and provide a report for the developer ))

From experience - we have checked web services, personal accounts, administrative panels, integrations, roles, forms, payment and accounting scenarios. Usually, we look at authorization, access rights, processing of user data, typical web vulnerabilities, business logic errors, APIs, environment settings, and risks before release.

The result - a working report for the developer.
- what was found
- where it manifests
- what is dangerous
- how to reproduce
- how to fix

The list does not show proposals concealed by the client or freelancer with a Plus profile, as well as proposals violating rules