I will pentest and secure your application source code
Offensive Security Engineer
Vetted by Fiverr Pro
Eric L was selected by the Fiverr Pro team for their expertise.
Vetted for
Cybersecurity
About this Gig
Vetted Pro
Secure Source Code Review Web, API & Mobile
6+ years in offensive security. Manual and tool-assisted code review aligned to OWASP ASVS, OWASP Top 10, and CWE Top 25, suitable for SOC 2, ISO 27001, HIPAA, and PCI-DSS.
Languages: Java/Kotlin, C#/.NET, PHP, Python, JavaScript/TypeScript, Go, Ruby, Swift, C/C++, Solidity
Scope:
- Injection SQLi, command, SSTI, XXE, NoSQL
- Auth & session passwords, MFA, JWT, OAuth/SSO
- Authorization BOLA/IDOR, privilege escalation
- Cryptography weak algorithms, hardcoded keys, randomness
- Input/output XSS, deserialization, path traversal, SSRF, file upload
- Business logic race conditions, workflow and payment bypass
- Secrets & config credentials, API keys, debug flags
- Dependencies vulnerable third-party libraries (SCA)
- Tooling Semgrep, CodeQL, SonarQube + full manual verification, no false positives
Deliverables:
- Executive summary for leadership and auditors
- Technical report with CVSSv4, CWE mapping, file/line references, PoC
- ASVS coverage matrix
- Remediation guidance with fixed code examples
- Prioritized remediation roadmap
- Retest (depends on the ordered package)
Industries: fintech, healthcare, crypto/Web3, SaaS, enterprise.
FAQ
Which languages and frameworks do you review?
Java/Kotlin, C#/.NET, PHP, Python, JavaScript/TypeScript, Go, Ruby, Swift, C/C++, and Solidity, including popular frameworks like Spring, Laravel, Django, Node, React, and Rails. If your stack isn't listed, message me and I'll confirm.
What do you need from me to get started?
Read-only access to the repository (GitHub, GitLab, Bitbucket, or a zip), a short description of the app and its critical functions, and the size of the codebase (lines of code). A build/run guide and architecture diagram are helpful but not required.
Is this an automated scan or a manual review?
Both. I use Semgrep, CodeQL, and SonarQube to cover the codebase quickly, then manually verify every finding and hunt for logic, auth, and business-flow flaws that scanners miss. You get zero false positives.
Do you review the backend, frontend, or both?
Both, plus mobile source and smart contracts if in scope. Authentication, authorization, APIs, data handling, and client-side logic are all covered.
How do you price and how long does it take?
Pricing depends on codebase size and complexity. Small codebases take a few days, larger ones one to two weeks. Send me your stack and lines of code for a fixed quote.
What does the final report look like?
An executive summary for leadership and auditors, a technical report with CVSSv4 scores, CWE mapping, file and line references, and proof of concept, an ASVS coverage matrix, and remediation guidance with fixed code examples.
Is my source code kept confidential?
Yes. I sign an NDA on request, work only in an isolated environment, and permanently delete all code and artifacts after delivery.
1 reviews for this Gig
| (1) | ||
| (0) | ||
| (0) | ||
| (0) | ||
| (0) |
Rating Breakdown
- Seller communication level
- Quality of delivery
- Value of delivery
Sort By
D didi756

United Kingdom
Ongoing collaborationthank you for your help
$50-$100
Price
3 days
Duration
Helpful?
1 reviews for this Gig
| (1) | ||
| (0) | ||
| (0) | ||
| (0) | ||
| (0) |
Rating Breakdown
- Seller communication level
- Quality of delivery
- Value of delivery
Sort By
D didi756

United Kingdom
Ongoing collaborationthank you for your help
$50-$100
Price
3 days
Duration
Helpful?
