I will perform a manual security audit of your android app
Junior Penetration Tester Web API and Android Security Testing
About this Gig
I'll manually test your Android application for real security vulnerabilities using static and dynamic analysis not just an automated scan.
What I test for:
Insecure local data storage (SharedPreferences, SQLite, plaintext secrets)
Certificate pinning weaknesses
Exported components (Activities, Services, Broadcast Receivers) that other apps could exploit
Deep link abuse and authentication bypass
Root-detection strength for sensitive apps (banking, finance, etc.)
Hardcoded API keys or secrets in the decompiled code
What you get:
A clear report with reproduction steps, severity rating, and remediation guidance
Practical, developer-friendly fixes, not just a list of problems
About me:
Certified Associate Penetration Tester (CAPT Hackviser) with hands-on experience testing Android applications professionally, using JADX, APKTool, and Proxifier.
️ I only test APKs you own or have explicit written authorization to test. Please confirm this and share the environment type (staging or production) before ordering.
Message me before ordering if you're unsure which package fits your app.
Testing application:
Mobile app
Development technology:
Java
•
JavaScript
•
Kotlin
•
PHP
Device:
Android mobile phone
FAQ
Do you need the source code, or just the APK file?
Just the APK is enough for most testing. Source code isn't required, though it can speed up static analysis if you're able to share it.
Is this staging or production testing?
I can test either, but please tell me which one before we start — staging allows more aggressive testing, while production requires more careful, limited testing to avoid affecting real users.
Do I need to give you a rooted device or emulator?
No — I use my own testing environment. I just need the APK file and confirmation that I'm authorized to test it.

