Full-Scope Laravel Penetration Test
Budget: $30 – $250 USD
I need an experienced penetration tester to perform a full security assessment (black-box + white-box) of a production-ready Laravel 10 web app with a MySQL backend hosted on a CentOS/AlmaLinux VPS. Focus: OWASP Top 10, with extra depth on XSS, access control/authorization, and security misconfiguration.
Scope:
Authentication / login flows, session management and roles
All data storage/retrieval paths (MySQL) and input validation
REST API endpoints and any file upload points
External black-box testing + white-box review (I can provide source access)
Deliverables:
Actionable report with findings, risk ratings, reproducible PoC steps or scripts, and remediation guidance
Executive summary for non-technical stakeholders
Raw logs, payloads and scripts used (so results are reproducible)
Please include your methodology (tools & manual steps), estimated timeline, and a fixed price (or milestone breakdown). I will provide an isolated staging environment, SSH/VPN access and quick responses to clarify scope.
Skills required
Penetration testing (web apps)
OWASP Top 10 experience
PHP / Laravel (v10) application security
REST API testing and authentication/authorization testing
MySQL / SQL injection testing (SQLMap knowledge helpful)
Burp Suite Pro / manual web exploitation skills
Linux (CentOS/AlmaLinux) and SSH/VPN testing experience
Report writing (clear, technical + executive summary)
Suggested timeline & budget (example to attract proposals)
Simple engagement: 2–4 days — $300–$800
Full medium engagement: 5–10 days — $800–$2,000
(If you want cheaper, post a lower budget but expect less depth; prefer fixed-price milestones: Recon + Scan; Exploitation + PoC; Final Report & Remediation.)
Quick screening questions to add to the posting
Have you tested Laravel apps before? Give a short example.
Which tools do you use (Burp, Nmap, SQLMap, custom scripts)?
Estimated days and fixed price for full OWASP Top 10 + report.
Can you provide a sample (redacted) report or PoC?
Scope:
Authentication / login flows, session management and roles
All data storage/retrieval paths (MySQL) and input validation
REST API endpoints and any file upload points
External black-box testing + white-box review (I can provide source access)
Deliverables:
Actionable report with findings, risk ratings, reproducible PoC steps or scripts, and remediation guidance
Executive summary for non-technical stakeholders
Raw logs, payloads and scripts used (so results are reproducible)
Please include your methodology (tools & manual steps), estimated timeline, and a fixed price (or milestone breakdown). I will provide an isolated staging environment, SSH/VPN access and quick responses to clarify scope.
Skills required
Penetration testing (web apps)
OWASP Top 10 experience
PHP / Laravel (v10) application security
REST API testing and authentication/authorization testing
MySQL / SQL injection testing (SQLMap knowledge helpful)
Burp Suite Pro / manual web exploitation skills
Linux (CentOS/AlmaLinux) and SSH/VPN testing experience
Report writing (clear, technical + executive summary)
Suggested timeline & budget (example to attract proposals)
Simple engagement: 2–4 days — $300–$800
Full medium engagement: 5–10 days — $800–$2,000
(If you want cheaper, post a lower budget but expect less depth; prefer fixed-price milestones: Recon + Scan; Exploitation + PoC; Final Report & Remediation.)
Quick screening questions to add to the posting
Have you tested Laravel apps before? Give a short example.
Which tools do you use (Burp, Nmap, SQLMap, custom scripts)?
Estimated days and fixed price for full OWASP Top 10 + report.
Can you provide a sample (redacted) report or PoC?
Related categories:
PHP
Linux
Web Security
Report Writing
MySQL
Laravel
Internet Security
Penetration Testing
RESTful API
Security