Laravel Payment Security Review
Budget: €30 – €250 EUR
I’m looking for an experienced application-security specialist to comb through the codebase of two Laravel-powered sites and harden every line that handles money or sensitive user data. This is a pure code-review engagement—no intrusive penetration testing on production servers—so you’ll be reading, annotating, and improving the PHP, Blade, and JavaScript that sit behind our checkout and login flows.
Scope to focus on
• Payment processing logic: gateways, callbacks, webhooks, error handling
• User authentication: sessions, tokens, password resets, 2FA hooks
• Database interactions: Eloquent queries, raw SQL, migrations, and any place user input is stored or retrieved
We follow our own internal, custom security guidelines, so I’ll share a concise checklist on kickoff. Your task is to map every relevant section of the code against that checklist, flag gaps, and propose concrete fixes that align with Laravel best practices and secure coding patterns (CSRF, prepared statements, proper hashing, etc.).
Deliverables
1. An annotated report that pinpoints each vulnerability or risky pattern, explains the risk in plain language, and references the specific file/line.
2. Recommended remediation steps or pull-request-ready patches where feasible.
3. A short debrief call or chat to walk through findings and answer developer questions.
You’ll be working in a private Git repository; familiarity with Git workflows, Composer, and Laravel 10 is a must. If you have tooling you prefer—static analyzers, linters, IDE plugins—feel free to use them, but the final output should stand on its own without requiring proprietary software.
Please highlight previous Laravel security reviews or any open-source contributions that demonstrate your expertise when you respond.
Scope to focus on
• Payment processing logic: gateways, callbacks, webhooks, error handling
• User authentication: sessions, tokens, password resets, 2FA hooks
• Database interactions: Eloquent queries, raw SQL, migrations, and any place user input is stored or retrieved
We follow our own internal, custom security guidelines, so I’ll share a concise checklist on kickoff. Your task is to map every relevant section of the code against that checklist, flag gaps, and propose concrete fixes that align with Laravel best practices and secure coding patterns (CSRF, prepared statements, proper hashing, etc.).
Deliverables
1. An annotated report that pinpoints each vulnerability or risky pattern, explains the risk in plain language, and references the specific file/line.
2. Recommended remediation steps or pull-request-ready patches where feasible.
3. A short debrief call or chat to walk through findings and answer developer questions.
You’ll be working in a private Git repository; familiarity with Git workflows, Composer, and Laravel 10 is a must. If you have tooling you prefer—static analyzers, linters, IDE plugins—feel free to use them, but the final output should stand on its own without requiring proprietary software.
Please highlight previous Laravel security reviews or any open-source contributions that demonstrate your expertise when you respond.