I will audit your laravel or node web app and fix security vulnerabilities


About this gig
You do not find out your app is insecure. Your users do.
WHAT I DO
I am a full stack engineer and independent security researcher. I audit Laravel, Node and React web apps the way a real attacker would, then I fix what I find. No generic scanner PDF, no scare tactics.
WHAT I CHECK
Broken authentication and session handling, IDOR and broken access control, SQL injection, XSS and CSRF, insecure file uploads, exposed secrets and .env leaks, vulnerable dependencies, weak token policy, missing rate limiting, misconfigured CORS and security headers, unsafe server setup.
WHAT YOU GET
A clear report with every finding, its severity, proof of concept and the exact fix. On Standard and Premium I also apply the fixes myself and retest, so you get a patched app instead of homework.
WHY ME
10+ years shipping production software. CTO at Nebula Solutions, where I have run platforms handling 200K peak users with zero downtime. I do security research on my own time, so I keep up with what actually gets exploited.
Message me with your stack and codebase size before ordering and I will tell you honestly which package you need.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Santiago Bugnon
Scalable solutions, built to last
- FromArgentina
- Member sinceJan 2023
Languages
English, Spanish
My Portfolio
FAQ
Is this a real manual audit or just an automated scan?
Both. I run tooling to cover the basics, then I manually test business logic, authentication and access control, which is where automated scanners miss the serious bugs.
Do you need access to my code and server?
Read access to the repo is enough for the audit. To apply fixes I need a staging environment or a branch, and server access only if we agreed on server hardening.
What if you do not find anything serious?
That is a good result and you still get the full report showing exactly what was tested. I also include hardening recommendations so the app stays safe as it grows.
Can you help if my app was already hacked?
Yes. I look for how they got in, clean the malicious code, close the hole and then harden the app so it does not happen again. Message me with what you saw before ordering.
Is my code and data kept confidential?
Always. I never share, publish or reuse anything I see. Findings stay between us and I delete my local copy of your codebase once the order is complete.

