PHP Site Vulnerability Pen-Test
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted1 hour ago
I want a seasoned penetration tester to put my PHP site through its paces and uncover every weakness, from classic SQL Injection and XSS to more sophisticated remote-code tricks. The public-facing pages matter, but my priority is the admin panel. Within that area I rely heavily on three features—CRUD data operations, role and permission management, and a file-upload module—so those have to be stressed especially hard.
Your job is to simulate real-world attacks with tools of your choice (Burp Suite, OWASP ZAP, manual source review, custom exploit scripts—whatever gets the most reliable results) and then document each vulnerability with a clear proof-of-concept, reproducible steps, severity rating, and a practical fix I can hand straight to my developer.
Deliverables
• Full penetration-test report (PDF or Markdown)
• Separate list of critical issues that require immediate patching
• Sanitised executive summary I can share with non-technical stakeholders
• A short debrief call or chat to walk me through findings and recommended remediation order
I will provide staging credentials and any extra information you need as soon as we start.
Your job is to simulate real-world attacks with tools of your choice (Burp Suite, OWASP ZAP, manual source review, custom exploit scripts—whatever gets the most reliable results) and then document each vulnerability with a clear proof-of-concept, reproducible steps, severity rating, and a practical fix I can hand straight to my developer.
Deliverables
• Full penetration-test report (PDF or Markdown)
• Separate list of critical issues that require immediate patching
• Sanitised executive summary I can share with non-technical stakeholders
• A short debrief call or chat to walk me through findings and recommended remediation order
I will provide staging credentials and any extra information you need as soon as we start.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.