Comprehensive Website/App QA & Security Check
Budget: $10 – $30 USD
I’m looking for a professional QA engineer to perform a functional QA test on my staging website/app. The primary goal is to validate core functionality and user flows, and improve overall UX. Additionally, include non-destructive, light security checks to surface trivial vulnerabilities (e.g., basic input validation issues, simple IDOR checks, or obvious reflected XSS) if present.
Scope:
Functional testing of core flows: registration/login, forms, profile, checkout/cart (if applicable), and key user journeys.
Cross-browser verification on Chrome and Firefox, plus basic mobile view checks.
Surface-level security checks (non-destructive): input validation, simple authorization checks (basic IDOR tests), and quick reflected XSS checks. No exploitation, no destructive payloads, no data exfiltration.
Testing limited to the provided staging environment / test accounts only.
Deliverables:
Short test plan / checklist within 24 hours of kickoff.
Organized Test Cases / Checklist (CSV, Excel, or Google Sheets).
Daily brief updates during the engagement.
Final report (PDF) including:
Executive summary.
Functional bug list with severity (High / Medium / Low).
Reproduction steps for each issue, expected vs actual behavior.
Notes and brief PoC (screenshots or short description) for any minor security issues found.
Recommended fixes and priorities.
Attachments: screenshots, short recordings (optional), and test logs if available.
Requirements:
Must follow non-destructive, ethical testing practices.
NDA available upon request.
Please attach a sample bug report or short portfolio entry (anonymized) with your proposal.
Preferred tools: Chrome DevTools, Postman (if API checks), basic scripting/tools as needed.
Budget & Timeline:
Budget: $10 – $30
Timeline: 1–4 days
How to apply:
Reply with a brief plan (1–3 sentences) of how you’ll approach the testing, an estimated delivery time within the range above, and a short example or sample report (anonymized).
Scope:
Functional testing of core flows: registration/login, forms, profile, checkout/cart (if applicable), and key user journeys.
Cross-browser verification on Chrome and Firefox, plus basic mobile view checks.
Surface-level security checks (non-destructive): input validation, simple authorization checks (basic IDOR tests), and quick reflected XSS checks. No exploitation, no destructive payloads, no data exfiltration.
Testing limited to the provided staging environment / test accounts only.
Deliverables:
Short test plan / checklist within 24 hours of kickoff.
Organized Test Cases / Checklist (CSV, Excel, or Google Sheets).
Daily brief updates during the engagement.
Final report (PDF) including:
Executive summary.
Functional bug list with severity (High / Medium / Low).
Reproduction steps for each issue, expected vs actual behavior.
Notes and brief PoC (screenshots or short description) for any minor security issues found.
Recommended fixes and priorities.
Attachments: screenshots, short recordings (optional), and test logs if available.
Requirements:
Must follow non-destructive, ethical testing practices.
NDA available upon request.
Please attach a sample bug report or short portfolio entry (anonymized) with your proposal.
Preferred tools: Chrome DevTools, Postman (if API checks), basic scripting/tools as needed.
Budget & Timeline:
Budget: $10 – $30
Timeline: 1–4 days
How to apply:
Reply with a brief plan (1–3 sentences) of how you’ll approach the testing, an estimated delivery time within the range above, and a short example or sample report (anonymized).