Full-Scope Laravel Penetration Test

Job ID: 39817451

Budget: $30 – $250 USD

I need an experienced penetration tester to perform a full security assessment (black-box + white-box) of a production-ready Laravel 10 web app with a MySQL backend hosted on a CentOS/AlmaLinux VPS. Focus: OWASP Top 10, with extra depth on XSS, access control/authorization, and security misconfiguration.

Scope:

Authentication / login flows, session management and roles

All data storage/retrieval paths (MySQL) and input validation

REST API endpoints and any file upload points

External black-box testing + white-box review (I can provide source access)

Deliverables:

Actionable report with findings, risk ratings, reproducible PoC steps or scripts, and remediation guidance

Executive summary for non-technical stakeholders

Raw logs, payloads and scripts used (so results are reproducible)

Please include your methodology (tools & manual steps), estimated timeline, and a fixed price (or milestone breakdown). I will provide an isolated staging environment, SSH/VPN access and quick responses to clarify scope.

Skills required

Penetration testing (web apps)

OWASP Top 10 experience

PHP / Laravel (v10) application security

REST API testing and authentication/authorization testing

MySQL / SQL injection testing (SQLMap knowledge helpful)

Burp Suite Pro / manual web exploitation skills

Linux (CentOS/AlmaLinux) and SSH/VPN testing experience

Report writing (clear, technical + executive summary)

Suggested timeline & budget (example to attract proposals)

Simple engagement: 2–4 days — $300–$800

Full medium engagement: 5–10 days — $800–$2,000
(If you want cheaper, post a lower budget but expect less depth; prefer fixed-price milestones: Recon + Scan; Exploitation + PoC; Final Report & Remediation.)

Quick screening questions to add to the posting

Have you tested Laravel apps before? Give a short example.

Which tools do you use (Burp, Nmap, SQLMap, custom scripts)?

Estimated days and fixed price for full OWASP Top 10 + report.

Can you provide a sample (redacted) report or PoC?