I will perform owasp web application security testing and vulnerability assessment


About this gig
Get an OWASP-aligned security assessment of your web application or API applicable risks identified, validated, mapped, and explained clearly.
Not every OWASP Top 10 category applies to every app. I test what's relevant to your architecture, not a generic checklist exercise.
WHAT YOU GET
OWASP-aligned discovery + applicable risk identification
Manual validation of findings (Standard & Premium)
CVSS-based severity, where applicable
OWASP-mapped findings with evidence
Practical remediation guidance
Structured assessment report
APPROACH
Scope review identify applicable OWASP risks automated discovery manual validation (Standard & Premium) severity, evidence, OWASP mapping structured report with remediation guidance.
SCOPE
One authorized web application OR API per engagement. Testing is based on what applies to your app not every OWASP category.
NOT INCLUDED
Destructive testing, unauthorized targets, remediation implementation, compliance certification claims, or retesting after remediation. Exploitation is limited to controlled proof-of-concept validation.
Not sure whether this or my broader Vulnerability Assessment gig fits better? Message me before ordering.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Arslan
Penetration Tester
- FromPakistan
- Member sinceAug 2025
- Avg. response time1 hour
Languages
English, German, Spanish
My Portfolio
FAQ
Will you test all 10 OWASP Top 10 categories?
Only the categories applicable to your application. I assess your architecture and features first rather than testing irrelevant categories just to complete a checklist.
Is this a full penetration test?
No. This is an OWASP-aligned web application security assessment with controlled, non-destructive validation of applicable risks. The exact scope is agreed before testing begins.
What's the difference between this and your Vulnerability Assessment gig?
This gig is specifically focused on web applications/APIs and OWASP mapping. My Vulnerability Assessment gig is broader and can cover web apps, APIs, or servers without the OWASP-specific mapping layer.
What do you need from me to start?
Your application/API details, confirmation that you own it or have authorization to test it, and a brief description of its features and architecture to help determine applicable risks.
Will testing affect my live application?
Testing is controlled and non-destructive. I do not perform denial-of-service or destructive testing. If your environment is fragile, please mention any testing restrictions before ordering.
Will you exploit vulnerabilities you find?
Only when necessary to confirm a finding through controlled proof-of-concept validation. Testing is non-destructive and does not go beyond what is needed to verify the issue.
What's the difference between the packages?
Basic provides OWASP-aligned automated discovery and analyst review. Standard adds manual validation, severity, evidence and remediation. Premium adds deeper testing and a consultation call.
What does a revision include?
A revision is a clarification or correction to the delivered report within the original scope. It does not include re-testing your application after you make changes.
Can you test more than one application?
Each package covers one defined web application or API scope. Additional applications or targets are not included automatically but can be discussed and separately scoped.
