Urgent Web App Vulnerability Scan
Budget: $250 – $750 AUD
A production-level web application needs an immediate, full-scope vulnerability scan. The goal is to uncover every exploitable weakness quickly and document clear, actionable fixes so my development team can patch without delay.
Scope & expectations
The assignment is strictly vulnerability scanning/penetration testing—automated reconnaissance backed by selective manual verification to weed out false positives. compliance audits are not required right now; speed and thorough coverage are.
Timeframe
Results are needed ASAP. If you can deliver a validated report within 24-48hours of access being granted, say so when you bid.
Tools & methodology
Feel free to employ OWASP ZAP, Burp Suite, Nessus, Qualys, or comparable industry tools that map well to OWASP Top 10 and CWE listings. I will not provide access to my site it all needs to be checked externally.
Deliverables (all required)
• Executive summary highlighting overall risk posture
• Detailed vulnerability report with CVSS scores, screenshots or PoCs, and remediation advice for each finding
• Raw scan logs/exports for internal verification
• One short hand-over call or recorded walkthrough to clarify critical issues
Acceptance criteria
• Every publicly reachable endpoint in the application is scanned at least once with authenticated and unauthenticated passes
• High- and critical-severity issues include reproducible proof and at least one mitigation strategy
• The final report is delivered in both PDF and editable format and passes a quick spot-check by my senior engineer.
Scope & expectations
The assignment is strictly vulnerability scanning/penetration testing—automated reconnaissance backed by selective manual verification to weed out false positives. compliance audits are not required right now; speed and thorough coverage are.
Timeframe
Results are needed ASAP. If you can deliver a validated report within 24-48hours of access being granted, say so when you bid.
Tools & methodology
Feel free to employ OWASP ZAP, Burp Suite, Nessus, Qualys, or comparable industry tools that map well to OWASP Top 10 and CWE listings. I will not provide access to my site it all needs to be checked externally.
Deliverables (all required)
• Executive summary highlighting overall risk posture
• Detailed vulnerability report with CVSS scores, screenshots or PoCs, and remediation advice for each finding
• Raw scan logs/exports for internal verification
• One short hand-over call or recorded walkthrough to clarify critical issues
Acceptance criteria
• Every publicly reachable endpoint in the application is scanned at least once with authenticated and unauthenticated passes
• High- and critical-severity issues include reproducible proof and at least one mitigation strategy
• The final report is delivered in both PDF and editable format and passes a quick spot-check by my senior engineer.