Security Audit & Enhancement for Wromble.dk
Budget / Salary$30–250
TypeFreelance project
LocationRemote
Posted2 hours ago
Job Posting: Security Audit & Remediation – Wromble.dk
Project: Wromble.dk – Security Audit & Remediation
We are looking for an independent security-focused developer to verify and complete the security work on our platform (website, backend, iOS app, Android app).
What has been done:
· A full security audit was completed by a previous freelancer (49 findings – critical, high, medium, low).
· Another developer has implemented fixes for many critical and high-severity issues: SQL injection, payment bypass, data leaks, stored XSS, chat access control, invoice IDOR, session cookies, CORS, MD5→bcrypt migration, database/Stripe key consolidation, blocking old code, and more.
· These fixes have not been independently verified.
What needs to be done:
· Verify that all previously reported vulnerabilities have been correctly fixed.
· Identify and fix any remaining security vulnerabilities.
· Test iOS and Android apps by building them from source code, comparing them with the versions in App Store and Google Play, and providing test links.
· Rotate any keys/secrets if required.
· Provide a full written security report and sign a Security Completion & Acceptance document.
· Provide a full project description and fixed price before starting.
Requirements:
· Strong experience with PHP, MySQL, Stripe, OWASP Top 10, and mobile app security.
· Experience testing iOS/Android apps from source code.
· Must sign a contract (provided) and agree to the terms before starting.
· Good English communication.
Please apply with:
· Your relevant experience.
· Estimated time.
· Fixed price for the entire project.
Project: Wromble.dk – Security Audit & Remediation
We are looking for an independent security-focused developer to verify and complete the security work on our platform (website, backend, iOS app, Android app).
What has been done:
· A full security audit was completed by a previous freelancer (49 findings – critical, high, medium, low).
· Another developer has implemented fixes for many critical and high-severity issues: SQL injection, payment bypass, data leaks, stored XSS, chat access control, invoice IDOR, session cookies, CORS, MD5→bcrypt migration, database/Stripe key consolidation, blocking old code, and more.
· These fixes have not been independently verified.
What needs to be done:
· Verify that all previously reported vulnerabilities have been correctly fixed.
· Identify and fix any remaining security vulnerabilities.
· Test iOS and Android apps by building them from source code, comparing them with the versions in App Store and Google Play, and providing test links.
· Rotate any keys/secrets if required.
· Provide a full written security report and sign a Security Completion & Acceptance document.
· Provide a full project description and fixed price before starting.
Requirements:
· Strong experience with PHP, MySQL, Stripe, OWASP Top 10, and mobile app security.
· Experience testing iOS/Android apps from source code.
· Must sign a contract (provided) and agree to the terms before starting.
· Good English communication.
Please apply with:
· Your relevant experience.
· Estimated time.
· Fixed price for the entire project.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.