Pen-Test Estimate for Marketplace
Budget: $750 – $1,500 USD
I’m wrapping up development on a multi-vendor marketplace that handles log-ins, bookings, payments, and file uploads, and I need an external penetration-testing partner. At this stage I only need an estimate of the effort and cost you would need to cover the scope below; the actual engagement will begin once our staging environment is ready.
Authentication & access
Our stack combines Nafath (Saudi SSO), Unifonic SMS OTP, and Google/Apple social log-ins. During the test you will have both admin-level and regular user credentials so you can look at every angle of privilege escalation.
Key areas to cover
• User dashboards
• Booking flow
• File uploads
• Payments, listing creation/edit, disputes, reviews & ratings
• Full admin portal
What I expect in your reply
• A realistic hour range (min–max) to sweep the items above, including API endpoints, payment webhooks, and standard vulnerability classes such as XSS, CSRF, SQLi and IDOR
• The tooling and methodology you follow—Burp Suite Pro, OWASP Testing Guide, or similar
• One or two sample reports you have produced (redacted is fine) so I can gauge clarity and depth
Deliverable for the eventual engagement
A written report that assigns severity to each finding (critical / high / medium / low) and provides concise remediation advice.
Please keep proposals focused on the estimate for now; the full brief and credentials will come once timelines are locked in.
Authentication & access
Our stack combines Nafath (Saudi SSO), Unifonic SMS OTP, and Google/Apple social log-ins. During the test you will have both admin-level and regular user credentials so you can look at every angle of privilege escalation.
Key areas to cover
• User dashboards
• Booking flow
• File uploads
• Payments, listing creation/edit, disputes, reviews & ratings
• Full admin portal
What I expect in your reply
• A realistic hour range (min–max) to sweep the items above, including API endpoints, payment webhooks, and standard vulnerability classes such as XSS, CSRF, SQLi and IDOR
• The tooling and methodology you follow—Burp Suite Pro, OWASP Testing Guide, or similar
• One or two sample reports you have produced (redacted is fine) so I can gauge clarity and depth
Deliverable for the eventual engagement
A written report that assigns severity to each finding (critical / high / medium / low) and provides concise remediation advice.
Please keep proposals focused on the estimate for now; the full brief and credentials will come once timelines are locked in.