Looks Like This Service Is On Hold
I will penetration test your website or web app with a fix ready security report


About this gig
Your website looks fine from the outside. That is exactly what attackers count on.
I am a developer first and a security tester second, which means I do not just dump a scanner report on you. I test the way an attacker would, then explain every finding in plain language with the exact fix, because I write PHP, MySQL and Node.js code every day and know where real apps break.
WHAT I TEST
OWASP Top 10: SQL injection, XSS, CSRF, broken auth, IDOR
Login, password reset, session and token handling
APIs and hidden endpoints
File uploads, admin panels, access control
Server config, headers, SSL, exposed files and backups
Business logic abuse (price tampering, privilege escalation)
WHAT YOU RECEIVE
A clean PDF report: every issue rated Critical to Low, proof of concept, screenshots, and a step by step fix. Premium includes me patching the code and retesting until it is clean.
GROUND RULES
I only test sites you own or have written permission for. Testing is careful and non destructive. Everything stays confidential and is deleted after delivery.
Send me your URL and a short note about the stack and I will confirm scope before you order.
Respect third-party rights
Please be aware that it is against Fiverr's policies for sellers to include themes, templates, or any other elements that infringe third-party rights or applicable laws in the delivered work. Read more about in our Guide to Responsible Digital Creation.
Get to know Mohammed A
Full Stack Web and Mobile App Developer
- FromSaudi Arabia
- Member sinceJul 2022
- Avg. response time1 hour
Languages
English, Arabic
FAQ
Will the testing break my live website?
No. I use safe, non-destructive techniques and never run denial-of-service or data-deleting tests. If you have a staging copy I will use that first.
What do you need from me to start?
The URL, written confirmation that you own it, and ideally a test user account. For Premium, access to the code repository or hosting so I can apply the fixes.
Is this a real manual test or just an automated scan?
Both. Scanners find the obvious things; I then test manually for logic flaws, access control and auth issues that scanners always miss. Every finding in the report is verified by hand.
