I will audit android app security, owasp masvs pentest, apk vulnerability report
About this gig
Is your Android app leaking API keys, storing data insecurely, or exposing components attackers can reach? I find out before they do.
I audit Android apps against the OWASP MASVS and MASTG standards and deliver a report your developers can act on immediately.
What I check:
- Hardcoded secrets: keys, tokens, credentials and endpoints inside the APK
- Insecure storage: SharedPreferences, SQLite, logs, cache, external storage
- Exported activities, services, receivers and content providers
- Network security: TLS validation, certificate pinning, cleartext traffic
- Authentication, session and token handling flaws
- Tamper resistance: obfuscation, root and debug detection
- Manifest and permission misconfiguration
What you get:
- Severity-rated findings with CVSS scores and clear reproduction steps
- Proof and screenshots for every confirmed issue
- Code-level remediation, not generic checklist advice
- An executive summary for non-technical stakeholders
- A free retest after you ship the fixes on Premium
I only test apps you own or are authorized to test. Message me first for free scoping.
Get to know Sharif Rafid
Full Stack Web And Mobile Apps Developer
- FromBangladesh
- Member sinceFeb 2017
- Avg. response time1 hour
- Last delivery3 months
Languages
Bengali, English
My Portfolio
Other Mobile App Development Services I Offer
FAQ
Do you need my source code, or just the APK?
The APK or AAB alone is enough for a full black-box audit, which is exactly how a real attacker sees your app. If you can share source, I add a code review and catch deeper logic and crypto issues. I confirm scope with you before starting either way.
Which security standard do you test against?
OWASP MASVS 2.0 for the requirements and the OWASP MASTG for the test procedures. Every finding maps to a specific MASVS control, so you can hand the report straight to a client, an auditor or an app store reviewer without rewriting it.
Will you test an app I do not own?
No. I need proof that you own the app or are authorised to test it, such as a contract, a written owner approval or a bug bounty scope. I confirm this before any testing starts, which keeps the engagement legal and the report usable.
Do you fix the issues or only report them?
Basic and Standard are assessment and report only. Premium includes hardening code patches plus a free retest once you deploy the fixes. On any package I stay available to answer your developers questions while they remediate.
Is my app and the report kept confidential?
Yes. Your binary, credentials, findings and report stay private and are never reused, published or shared. I delete test builds and captured data after delivery on request, and I am happy to work under your NDA.

