I will penetration test your website and API for vulnerabilities


About this gig
Is your website or API secure enough to withstand real-world attacks?
I provide professional Web & API Penetration Testing to identify security vulnerabilities before attackers can exploit them.
My testing focuses on:
- Authentication & authorization
- IDOR / BOLA
- API security
- Business logic flaws
- Privilege escalation
- OWASP Top 10 vulnerabilities
- Session and access-control issues
- Input validation and data exposure
I combine automated security tools with manual testing to validate real risks and reduce false positives.
You will receive a clear, professional report including vulnerability details, severity, evidence/PoC, impact, reproduction steps, and practical remediation guidance. Retesting is available where included in the selected package.
I have worked in cybersecurity since 2020, with experience in authorized application testing, vulnerability research, and 250+ private-company web applications.
All testing is performed only on systems you own or are explicitly authorized to have tested.
Please contact me before ordering so we can confirm your scope, target, user roles, API documentation, and testing
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Emon
Security Just illusion
- FromBangladesh
- Member sinceMay 2021
- Last delivery8 months
Languages
Bengali, English
Other Website Maintenance Services I Offer
FAQ
1. What do you need before starting the penetration test?
Please provide the target URL, authorized test environment, test accounts/user roles, API documentation if applicable, and testing scope.
2. Do you perform manual penetration testing?
Yes. I combine automated tools with manual security testing to validate vulnerabilities and identify issues that automated scanners may miss.
3. Can you test APIs?
Yes. I can assess REST APIs and other supported API environments for authentication, authorization, BOLA/IDOR, business logic, data exposure, and related vulnerabilities.
5. Will I receive a security report?
Yes. You will receive a professional report containing findings, severity, evidence/PoC, impact, reproduction steps, and remediation recommendations.
6. Can you test a large SaaS application?
Yes. For large applications, multiple environments, many user roles, or extensive APIs, please contact me first so I can create a custom offer based on the actual scope.

