Frappe App Security Pen Test
Budget: $10 – $30 USD
My custom ERPNext / Frappe application is live and handling sensitive business data, so I need a thorough application-level penetration test carried out strictly under OWASP methodology. The scope is the full web stack exposed by the app: all HTTP(S) endpoints, client-side code, server-side logic and the REST API.
Please exercise the assessment as a real-world attacker would—manual testing supported by tools such as Burp Suite, OWASP ZAP, or equivalent—then document every confirmed vulnerability with clear reproduction steps and risk ratings. Where possible, include a practical fix or mitigation I can implement directly in the Frappe framework.
Deliverables
• Executive-level summary (non-technical)
• Detailed technical report covering findings mapped to OWASP Top 10, proof-of-concept payloads, and screenshots/logs
• Prioritised remediation roadmap
• Optional short re-test once fixes are deployed (quote hours separately)
All testing must be non-disruptive to production; I will provide a staging URL and credentials.
Please exercise the assessment as a real-world attacker would—manual testing supported by tools such as Burp Suite, OWASP ZAP, or equivalent—then document every confirmed vulnerability with clear reproduction steps and risk ratings. Where possible, include a practical fix or mitigation I can implement directly in the Frappe framework.
Deliverables
• Executive-level summary (non-technical)
• Detailed technical report covering findings mapped to OWASP Top 10, proof-of-concept payloads, and screenshots/logs
• Prioritised remediation roadmap
• Optional short re-test once fixes are deployed (quote hours separately)
All testing must be non-disruptive to production; I will provide a staging URL and credentials.