CMS Pen Test & Audit
Budget: €250 – €750 EUR
I’m looking for an experienced web-security professional who can move fast and dig deep into my content-management system. The job covers three fronts—penetration testing, a thorough vulnerability assessment, and a full security audit—so I can understand exactly where my CMS is exposed and how to close the gaps.
Scope
• Simulate real-world attacks (external, authenticated, and privilege-escalation scenarios) against the live CMS, following OWASP Top 10 and business-logic abuse cases.
• Run automated scans and manual verification with industry-standard tools such as Burp Suite, OWASP ZAP, Nmap, Nikto, and custom scripts where needed.
• Review server, database, and file-permission configurations for misconfigurations or outdated components.
• Deliver a clear, prioritised report that includes: executive summary, reproducible proof-of-concept steps, risk ratings, and a remediation roadmap.
• Wrap up with a brief walkthrough call so I can address any follow-up questions.
Logistics
I can supply staging credentials, limited production access, and VPN keys immediately. First insights are needed ASAP—ideally a preliminary findings snapshot within a week and the full report shortly after.
Confidentiality and professionalism are essential; all findings stay strictly between us. If you have a strong track record in CMS security and can start right away, I’d love to hear how you would approach the engagement and which methodologies you prefer.
Scope
• Simulate real-world attacks (external, authenticated, and privilege-escalation scenarios) against the live CMS, following OWASP Top 10 and business-logic abuse cases.
• Run automated scans and manual verification with industry-standard tools such as Burp Suite, OWASP ZAP, Nmap, Nikto, and custom scripts where needed.
• Review server, database, and file-permission configurations for misconfigurations or outdated components.
• Deliver a clear, prioritised report that includes: executive summary, reproducible proof-of-concept steps, risk ratings, and a remediation roadmap.
• Wrap up with a brief walkthrough call so I can address any follow-up questions.
Logistics
I can supply staging credentials, limited production access, and VPN keys immediately. First insights are needed ASAP—ideally a preliminary findings snapshot within a week and the full report shortly after.
Confidentiality and professionalism are essential; all findings stay strictly between us. If you have a strong track record in CMS security and can start right away, I’d love to hear how you would approach the engagement and which methodologies you prefer.