Security Review for new mobile Member App/API
Budget / Salary€1,000–4,000
TypeFreelance project
LocationRemote
Posted1 day ago
We need an independent security review of a new member app (React Native / Expo) and its PHP JSON API. This is not a redesign or a feature build.
The previous generation of this product had a serious incident (personal data exposed). That stack is retired. We want a review of the new app and API before a wider release.
This is a small member app for people who already belong to a venue/club. It is not a marketplace, social network, or payments app.
What it does today (this is the whole product):
- Sign in, create account, verify email, reset password (reset is a simple web page)
- 8 languages
- Accept terms when they change
- Home: greeting, shortcuts; optional club “home” when a club is selected
- Clubs: list of linked clubs, pending/unavailable states, add a club with a code (connects an existing membership; staff finish the link)
- Profile: name, photo if the club has one, credit, member type, membership status, QR to show on site
- Log out
What it does not do:
- No chat, feed, map, camera KYC, in-app payments, or admin tools
- No browsing or “joining” random clubs from the app
- Staff-side club software is a separate system and is out of scope unless we say otherwise
Size (for quoting):
- One React Native / Expo app (iOS + Android, same code)
- A small PHP JSON API: on the order of ~12 endpoints (login, session, register, password reset, profile, add-club, languages, etc.)
- A few static web pages (verify email, reset password)
We expect a short, time-boxed review (days, not weeks), not a full enterprise pentest, unless you explain why more time is needed.
What we will provide (after hire, not in this post):
- TestFlight / Android preview builds
- A throwaway member account
- Read-only or time-limited access to the API source and app source under NDA
- A written scope and rules of engagement
In scope:
- iOS and Android client (same codebase)
- Public HTTPS API used by the app (login, session, registration, password reset, profile, club linking)
- Auth: passwords, sessions, email verification, password reset
- Access control: one member must not read or change another member’s data or another club’s data
- Secrets in the client, local storage, logging
- Transport (HTTPS), session handling, rate limiting, common API issues (auth bypass, IDOR, injection, mass assignment)
- High-level review of server exposure of private folders / config (no full infra pentest unless agreed)
Out of scope (unless we agree in writing):
- Denial of service / load testing
- Other products or domains we have not named
- Phishing our staff or testers
- Accessing real customer or club production data
- Social engineering
- Publishing findings before we have had time to fix them
What we are not asking for:
- A rewrite of the app
- “Unpack the APK and send us exploits”
- A generic automated scan dump with no explanation
Deliverables:
- A written report: findings, severity (e.g. Critical / High / Medium / Low / Info), affected endpoint or component, impact, and a clear fix recommendation.
- A short call to walk through the report.
- Re-test of issues we mark as fixed (within an agreed window).
How you should work:
- Time-boxed (please bid a number of days, not “until we find something”).
- Use only the test account and systems we name.
- Stop and tell us immediately if you find live personal data you should not have.
- No public write-up or CVE without our written OK.
Please include in your bid:
- 2–3 similar mobile + API reviews (no need to name clients if under NDA)
- Whether you prefer source-assisted or black-box, and why
- Your report sample (redacted is fine)
- Fixed price and number of days
- Confirmation you will sign an NDA
- We will not share production admin credentials or the live database with freelancers. Testers use a dedicated account.
The previous generation of this product had a serious incident (personal data exposed). That stack is retired. We want a review of the new app and API before a wider release.
This is a small member app for people who already belong to a venue/club. It is not a marketplace, social network, or payments app.
What it does today (this is the whole product):
- Sign in, create account, verify email, reset password (reset is a simple web page)
- 8 languages
- Accept terms when they change
- Home: greeting, shortcuts; optional club “home” when a club is selected
- Clubs: list of linked clubs, pending/unavailable states, add a club with a code (connects an existing membership; staff finish the link)
- Profile: name, photo if the club has one, credit, member type, membership status, QR to show on site
- Log out
What it does not do:
- No chat, feed, map, camera KYC, in-app payments, or admin tools
- No browsing or “joining” random clubs from the app
- Staff-side club software is a separate system and is out of scope unless we say otherwise
Size (for quoting):
- One React Native / Expo app (iOS + Android, same code)
- A small PHP JSON API: on the order of ~12 endpoints (login, session, register, password reset, profile, add-club, languages, etc.)
- A few static web pages (verify email, reset password)
We expect a short, time-boxed review (days, not weeks), not a full enterprise pentest, unless you explain why more time is needed.
What we will provide (after hire, not in this post):
- TestFlight / Android preview builds
- A throwaway member account
- Read-only or time-limited access to the API source and app source under NDA
- A written scope and rules of engagement
In scope:
- iOS and Android client (same codebase)
- Public HTTPS API used by the app (login, session, registration, password reset, profile, club linking)
- Auth: passwords, sessions, email verification, password reset
- Access control: one member must not read or change another member’s data or another club’s data
- Secrets in the client, local storage, logging
- Transport (HTTPS), session handling, rate limiting, common API issues (auth bypass, IDOR, injection, mass assignment)
- High-level review of server exposure of private folders / config (no full infra pentest unless agreed)
Out of scope (unless we agree in writing):
- Denial of service / load testing
- Other products or domains we have not named
- Phishing our staff or testers
- Accessing real customer or club production data
- Social engineering
- Publishing findings before we have had time to fix them
What we are not asking for:
- A rewrite of the app
- “Unpack the APK and send us exploits”
- A generic automated scan dump with no explanation
Deliverables:
- A written report: findings, severity (e.g. Critical / High / Medium / Low / Info), affected endpoint or component, impact, and a clear fix recommendation.
- A short call to walk through the report.
- Re-test of issues we mark as fixed (within an agreed window).
How you should work:
- Time-boxed (please bid a number of days, not “until we find something”).
- Use only the test account and systems we name.
- Stop and tell us immediately if you find live personal data you should not have.
- No public write-up or CVE without our written OK.
Please include in your bid:
- 2–3 similar mobile + API reviews (no need to name clients if under NDA)
- Whether you prefer source-assisted or black-box, and why
- Your report sample (redacted is fine)
- Fixed price and number of days
- Confirmation you will sign an NDA
- We will not share production admin credentials or the live database with freelancers. Testers use a dedicated account.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.