Comprehensive Website Security Audit & Fix
Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted1 hour ago
I have a production-ready site that was stitched together by several freelancers. While the feature set works, the underlying security clearly does not: I can already spot areas where input is not sanitised and session handling feels weak. I now need a professional who can take the codebase apart, find every vulnerability, patch it, and then prove the fixes hold under pressure.
Here is what I am looking for:
• A full secure-code review of the existing PHP/Laravel and JavaScript stack, line by line where necessary, identifying logic flaws, misconfigurations, and any OWASP Top 10 issues.
• Active penetration testing once the review is complete, so we validate your fixes in a real-world scenario rather than stopping at theoretical findings.
• Clear, developer-ready remediation: update the code yourself, comment the changes, and supply a concise report that maps each vulnerability to its patch and retest results.
The most critical areas—user authentication, payment processing, data storage, and really anything that could be abused—must emerge bullet-proof when you are done. Please show relevant past work (redacted reports or links to resolved CVEs are ideal) so I can see the depth of your experience. If you routinely combine static analysis tools (Burp Suite, OWASP ZAP, SonarQube, etc.) with manual review, mention that as well.
I will grant repository access after NDA. Final acceptance happens only after we rerun penetration tests and everything comes back clean.
Here is what I am looking for:
• A full secure-code review of the existing PHP/Laravel and JavaScript stack, line by line where necessary, identifying logic flaws, misconfigurations, and any OWASP Top 10 issues.
• Active penetration testing once the review is complete, so we validate your fixes in a real-world scenario rather than stopping at theoretical findings.
• Clear, developer-ready remediation: update the code yourself, comment the changes, and supply a concise report that maps each vulnerability to its patch and retest results.
The most critical areas—user authentication, payment processing, data storage, and really anything that could be abused—must emerge bullet-proof when you are done. Please show relevant past work (redacted reports or links to resolved CVEs are ideal) so I can see the depth of your experience. If you routinely combine static analysis tools (Burp Suite, OWASP ZAP, SonarQube, etc.) with manual review, mention that as well.
I will grant repository access after NDA. Final acceptance happens only after we rerun penetration tests and everything comes back clean.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.