Full-Stack Marketplace Security Audit

via Freelancer ·

Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted2 hours ago
I’m looking for a seasoned security professional to run a deep-dive audit across both the frontend and backend of my online marketplace. My main concern is tightening anything that touches user authentication (currently session-based) and the way we store data— from database configuration through to file uploads and logs.

Here’s what I need from you:
• A penetration-style assessment of the live site and its APIs, using common tools such as OWASP ZAP or Burp Suite alongside manual exploration.
• A code-level review that zeroes in on the session-handling logic, cookie flags, CSRF protections, and any spots where sensitive data might inadvertently be logged or cached.
• Database and storage inspection to confirm encryption at rest, least-privilege access, and safe backup practices.
• A concise report summarising every discovered issue, ranked by severity, with practical remediation steps I can hand straight to my dev team.

Acceptance criteria
• Every critical or high-risk finding clearly documented with a reproducible proof-of-concept.
• Actionable fixes for medium-risk issues or clear justification when no change is required.
• A final walkthrough call to verify corrections and answer questions.

While payment workflows exist, they’re already handled by a third-party provider and are not the primary focus right now— but if you spot related weaknesses as you work, flag them. Let’s make sure our user sessions stay locked down and our data stays private.
web security computer security mysql database administration internet security penetration testing api testing security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.