I will audit your web app for security vulnerabilities and fix them


About this gig
Here's the description paste it in:
I audit Node.js, Next.js and API backends for real security vulnerabilities broken access control, IDOR, PII exposure, missing rate limiting, injection, and authentication flaws. You get a clear, prioritised report (Critical to Low) with the exact file and line for each issue and a concrete fix.
What I check:
- Authentication and session handling
- Access control and IDOR (can users reach data that is not theirs?)
- PII and sensitive data exposure
- Injection, unsafe input handling, and insecure defaults
- Rate limiting and abuse protection
This is a genuine manual review by a developer, not an automated scanner dump. I have audited regulated production platforms and caught live access-control and data-exposure bugs before they shipped.
Message me with your stack before ordering so I can scope it accurately.
Get to know Noah S
Full Stack Developer for Web Apps and Web Scraping
- FromAustralia
- Member sinceMay 2016
- Avg. response time1 hour
Languages
English
My Portfolio
Other Software Development Services I Offer
FAQ
What do you need from me?
Access to your codebase (or the relevant parts) and a short description of your stack and what the app does.
Is this automated or manual?
Manual. I read the actual code and logic. Automated scanners miss access-control and business-logic flaws, which are often the most damaging.
Do you fix the issues or just report them?
The Basic and Standard tiers are report-only. The Premium tier includes me implementing and re-testing the top-priority fixes.
Will you keep my code confidential?
Yes. I treat all code and findings as confidential and can work under an NDA if you need one.
