
In Progress
Posted
Paid on delivery
Security Audit – Website & iOS/Android Apps We are looking for a developer/security specialist to perform a 5-day security review and manual testing of our website, backend and iOS/Android apps. The work includes: * Review and test Stripe integration, API keys, webhooks, payments, refunds, chargebacks, MobilePay and Apple Pay. * Review GDPR/security of personal data, access control, encryption, storage and deletion. * Manual review based on OWASP Top 10, including SQL Injection, XSS, CSRF, authentication, authorization and exposed API endpoints. * Test iOS and Android apps, including installation, login, backend communication, payments and data. * Review server/app logs, monitoring, PHP and other system versions. * Identify and report security risks and provide recommendations. Important requirements: * All sensitive credentials must be reviewed and, where required, changed/rotated and secured, including API keys, secret keys, webhook secrets, passwords and database credentials. * On Day 1, the freelancer must identify and inform us of all credentials/services that he cannot access and that we need to change or provide access to ourselves. * Access will initially be provided to FTP via SSH, control panel and Stripe. If additional access is required, the freelancer must request it from us. * Everything done must be documented, including tests performed, changes made, credentials/keys rotated, issues found, files delivered and configurations reviewed. * No hidden accounts, backdoors or unauthorized access may be created or left behind. * A final written security report must be delivered. * 5 working days total, including any delays. * Fixed price: $175 USD, paid through Freelancer.com in 2 milestones. * 2 weeks of free support after final delivery and final milestone payment. * All files, credentials, source code and information are strictly confidential and may not be shared with anyone. * All access and copies of files must be removed when the cooperation e
Project ID: 40678198
57 proposals
Remote project
Active 7 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
57 freelancers are bidding on average $135 USD for this job

Hello, I understand the critical need for a thorough security review of your website, backend, and iOS/Android apps. As a seasoned cybersecurity specialist, I am well-equipped to handle the complexities involved in this project. My approach will involve a meticulous examination of your Stripe integration, API keys, webhooks, payments, GDPR compliance, and more. I will conduct manual testing based on OWASP Top 10 standards to identify and address vulnerabilities such as SQL Injection, XSS, and CSRF. Additionally, I will thoroughly review server logs, monitor system versions, and ensure data encryption and access control measures are robust. Rest assured, I will provide detailed documentation of all tests conducted, changes made, and issues found. Your sensitive credentials will be handled with utmost care, and I will deliver a comprehensive security report at the project's conclusion. I invite you to open a chat to discuss how I can enhance the security posture of your platform. Let's collaborate to fortify your digital assets and ensure airtight protection against potential threats. Sincerely, Rajesh
$140 USD in 10 days
9.4
9.4

Your five-day review needs more than an automated scan: it requires hands-on validation of the website, PHP/MySQL backend, Stripe flows, iOS/Android apps, privacy controls, and operational security. I will begin on Day 1 by inventorying every required credential and service, clearly marking anything unavailable so you can provide or rotate it. I will work only through the supplied SSH/FTP, control panel, Stripe, and any additional access you approve. I will test authentication, authorization, session handling, SQL injection, XSS, CSRF, exposed endpoints, API-key leakage, webhook signature validation, payment/refund/chargeback logic, MobilePay and Apple Pay flows, and sensitive-data storage, encryption, retention, and deletion. I will install and exercise both mobile apps through login, backend communication, payments, and local data inspection. I will also review logs, monitoring, server and PHP versions, database permissions, and configuration weaknesses. All findings will include severity, evidence, impact, reproduction steps, and practical remediation. I will document every test, reviewed configuration, file change, credential/key rotation, delivered file, and cleanup action. No accounts or backdoors will be left behind; access and temporary copies will be removed at completion. You will receive a final written report plus two weeks of support after delivery. Muhammad Saad
$175 USD in 5 days
7.8
7.8

Hi, I checked your "Perform 5-Day Comprehensive Security Review -- 2" project description, it looks like the focus is on delivering a clean, responsive website that works well across all devices. I prefer understanding the expected layout and user experience first, then building pages that closely match the design while keeping the code organized and easy to maintain. Feel free to share the design or current website, and I'll suggest the best implementation along with a realistic timeline. Final timeline and cost will be confirmed in chat after a complete understanding and documentation of the project expectations in detail.
$98 USD in 4 days
7.4
7.4

Hi, I see you need a comprehensive security review for both your website and iOS/Android apps which involves deep vulnerability testing across multiple platforms. A hidden challenge here is ensuring the security measures cover both web and mobile environments seamlessly without disrupting user experience. Smart Sols specializes in Laravel, Native PHP, and Flutter-based apps, backed by a decade of experience which equips us well to handle complex cross-platform security audits. What specific security standards or compliance requirements are you aiming to meet with this audit? Let's secure your apps effectively—are you available to discuss the project timeline?
$213 USD in 7 days
6.9
6.9

Hello!! Your PHP application can undergo a focused 10-day security audit to identify vulnerabilities, configuration weaknesses, authentication issues, and other security risks, followed by practical remediation and validation. * What PHP framework and database does the application use? * Is there a staging environment available for the security testing? * Do you need vulnerabilities fixed during the 10-day engagement or only documented in the final report? The workflow will include application and API security assessment, authentication and authorization testing, input-validation checks, session and access-control review, dependency and configuration analysis, database security checks, security-header review, vulnerability prioritization, remediation guidance, and retesting of resolved issues. Each finding will be documented with its severity, affected component, evidence where appropriate, potential impact, and recommended fix. Testing will remain within the authorized scope to avoid disrupting production systems. Relevant PHP, Laravel, API, database, application-security, and vulnerability-assessment projects have been completed before, with a focus on identifying practical risks and providing actionable fixes. Let us confirm the application scope, testing environment, and required deliverables so we can structure the 10-day audit effectively. Best regards Farhin B
$100 USD in 3 days
6.8
6.8

Hi, I'm Denis, a developer who has conducted security reviews for similar web and mobile applications. I understand you need a comprehensive 5-day review focusing on credentials, integrations, data protection, and OWASP risks across your website and apps. I’ll methodically check Stripe flows, payment handling, and sensitive data handling while verifying encryption, access controls, and exposed endpoints. The audit will include manual testing of iOS/Android apps, log reviews, and server configuration checks. All credentials will be rotated where needed, and findings will be clearly documented in a final report. Access limitations will be flagged on Day 1 to avoid delays. Risks like hidden backdoors or incomplete access will be addressed by validating every permission and configuration change before finalizing. The work will stay confidential, with all access removed post-review. I can start working right away. Let's connect and discuss the details. Thanks, Denis.
$150 USD in 2 days
6.1
6.1

Hello There! I’m Md Toriqul Islam, an experienced full-stack developer with strong expertise in web/mobile security, APIs, Stripe integrations, authentication, databases, and secure application architecture. I have rich experience reviewing web applications and APIs, testing OWASP Top 10 vulnerabilities, authentication/authorization, payment workflows, exposed endpoints, data protection, server configurations, and application security. I understand you need a complete 5-day manual security audit covering your website, backend, iOS/Android apps, Stripe, Apple Pay, MobilePay, GDPR-related data handling, credentials, logs, and infrastructure. I’m skilled in OWASP testing, API security, PHP, databases, mobile/backend communication, Stripe webhooks, access control, encryption, and secure credential management. A few questions: 1) Will you provide test accounts, test payment credentials, and iOS/Android test builds on Day 1? 2) Are there any known security concerns or previous audit findings you want prioritized? 3) Will production credential rotation be performed by me with your approval, or should I provide the rotation plan for your team? I’ll document every test, finding, change, credential rotation, and configuration reviewed, and deliver the final security report within 5 working days. Looking forward to hearing from you. Best regards, Md Toriqul Islam
$100 USD in 3 days
5.9
5.9

I’ve audited Stripe integrations, OWASP Top 10 vectors and mobile app stacks before—this fits squarely in my domain. Day 1 starts with an access inventory to flag missing credentials upfront, then I’ll map Stripe webhook signatures, API keys and MobilePay/Apple Pay endpoints for leakage. Static/dynamic scans will target SQLi, XSS, CSRF and authz gaps, while app traffic will be intercepted via proxyman/Charles to validate certificate pinning and data storage. Logs and PHP/MySQL versions will be cross-checked against CVEs, and all rotated secrets logged with rollback steps. No persistent artifacts remain after sign-off. I can start immediately. Thanks, Andrii.
$175 USD in 2 days
5.2
5.2

Hi, The most likely immediate risk is exposed Stripe API keys and other sensitive credentials stored in code repositories or config files, combined with insufficient server-side logging and missing controls for Broken Access Control and Sensitive Data Exposure under OWASP Top 10. I have led security reviews for a payroll API and a mission-critical tax filing system where I located leaked credentials, tightened token scopes, and implemented secure logging and retention policies while maintaining GDPR constraints. In those engagements I performed manual app testing, reviewed mobile clients, audited server/app logs, and delivered a prioritized remediation report with proof-of-fix verification. On Day 1 I will identify credentials/services requiring access changes and send a clear action list before making any changes. My first technical action will be a credential inventory and targeted static scan of config and repository files, followed by runtime verification of Stripe integration and token usage. I will manually test web backend and iOS/Android apps against OWASP Top 10 items relevant to your stack and review server/app logs for suspicious activity. I will document every test, every change, and every finding. I will not create any hidden accounts or unauthorized access. Final delivery will be a written security report plus two weeks of free support. I acknowledge the fixed price of $175 USD, paid in 2 milestones through Freelancer.com, and the confidentiality requirement. - Do you want me to start with FTP via SSH and Stripe access only, or should I request control panel access on Day 1? - Are there any recent log retention or GDPR data deletion policies I should review before testing? Best regards, Thomas Beigbeder
$210 USD in 3 days
5.3
5.3

The main concern is covering the full attack surface in five days without treating automated scans as a security review. I’d manually test the PHP backend and APIs against OWASP Top 10, trace authentication/authorization and payment flows including Stripe webhooks, then review the iOS/Android clients, storage, logs, encryption, and credential exposure. I’d keep a documented evidence trail for each finding and clearly separate vulnerabilities from configuration issues. On Day 1, which environments and app builds will be available for testing alongside the initial SSH/control-panel/Stripe access?
$250 USD in 5 days
4.9
4.9

Hi there, I can carry out the full 5-day security review across your website, backend, Stripe/payment flows and iOS/Android apps, with a practical focus on finding real weaknesses rather than producing a generic automated scan. I’ll manually assess authentication, authorization, APIs, SQLi, XSS, CSRF, exposed secrets, webhook/payment handling, encryption, data storage and GDPR-related risks, alongside server and application configuration. I’ll document every test, finding, affected component and recommended remediation, while carefully tracking any credential rotation or configuration change. No hidden accounts, backdoors or unnecessary access will be introduced, and I’ll provide the final written report plus the requested handover documentation. I think you want a security review that leaves you with a clear, defensible picture of what is actually exposed and what needs fixing first, not simply a list of scanner alerts. Looking forward to work with you. Thanks
$200 USD in 3 days
5.1
5.1

Hi, there - Truong here. "5-DAY COMPREHENSIVE SECURITY REVIEW" - you need every security gap across your website, backend, payments, APIs, and mobile apps found and documented. I would map each day to OWASP Top 10 testing, credential review and payment/API checks, with every test, change, rotation and finding recorded. This makes the 5-day review fully traceable. One edge case is a leaked or over-privileged API or webhook credential. I would verify permissions, trace where it is used, recommend rotation, and document the required fix without leaving any hidden access behind. Which test accounts and app builds can you provide on Day 1? Thank you.
$30 USD in 2 days
4.8
4.8

Hey, this review needs to trace the security boundary across the website, backend, mobile apps, and payment flows—not just run an OWASP checklist—especially since credentials, Stripe webhooks, personal data, and mobile API access all intersect. I’d start Day 1 by mapping the exposed services and credential dependencies, then manually trace authentication and authorization from each client into the backend. For Stripe, I’d specifically verify that payment/refund state is derived from authenticated server-side webhook events rather than client-side success responses, while testing API exposure and data-access controls across web and mobile. Every test and configuration change would be recorded, including credential rotations and remediation evidence, with the final report separating confirmed findings from recommendations. Access would remain strictly within the authorized environment. Is there a staging environment available for tests that could affect payment or production data?
$150 USD in 5 days
4.5
4.5

⚠️ If you're not happy, you don’t pay. ⚠️ Hi, Thank you for checking my proposal and sharing the detailed project brief. I can perform a comprehensive security audit of your website and iOS/Android apps using best practices and tools, ensuring a secure environment for your users. I will deliver: • In-depth review of Stripe integration, API keys, webhooks, and payment systems • Evaluation of GDPR compliance and personal data protection, including access control and encryption • Manual testing based on OWASP Top 10 for vulnerabilities like SQL Injection and XSS • Detailed assessment of mobile apps, covering installation, login, and backend communication • Comprehensive analysis of server/app logs and system versions • Full documentation of findings, changes, and identified risks • A final written security report You will also receive: • 2 weeks of complimentary support post-delivery I am confident I can execute your vision professionally and efficiently. Looking forward to discussing the timeline and next steps. Best regards, Chirag Pipal
$150 USD in 7 days
4.3
4.3

Hello, I checked your project "Perform 5-Day Comprehensive Security Review -- 2" and already have a clear understanding of your requirements and how to deliver them efficiently. I have solid experience in PHP, MySQL, and I've successfully completed similar projects by delivering high-quality, scalable, and reliable solutions. Why choose me? * Strong expertise in PHP, MySQL * Clean, optimized, and scalable implementation * Fast communication and regular progress updates * Focused on delivering results, not just completing the task I'm ready to start immediately and would be happy to discuss the details. Best regards, Umer
$30 USD in 1 day
4.0
4.0

Hello sir, Did go through your job description and glad to share that I have enormous experience in working with Perform 5-Day Comprehensive Security Review I'm a seasoned programmer and Engineer with quality experience in Flutter, React, Node.JS, SpringBoot, Frontend and Backend Development, Python, Matlab, R studio, C, C++, C#, OpenCV, OpenGL, Tesseract OCR, google vision, Statisticaal programming/R progamming data analysis Computing for Data Analysis Time Series & Econometric, Machine learning, AI, Deep learning, Matlab and Mathematica, 3D modeling, CAD/CAM,AutoCAD, 2D, Architectural Engineering, SolidWorks, Unity 3D, AutoCAD, 2D drawing, 2D draftingPCB, Electronics, Arduino, Embedded Systems Automation, Embedded and Firmware , IOT, Electrical/Mechanical Engineering I am a TOP Rated Freelancer, and you can check my reviews here as well: https://www.freelancer.com/u/mzdesmag. Looking forward to potentially working together on this project. Thanks and Best regards, Adekunle.
$175 USD in 5 days
4.2
4.2

Hi, I am a web security specialist with 8 years of rich experience in software development and security testing. I am familiar with PHP, MySQL, OWASP Top 10, Stripe, Apple Pay, MobilePay, API and mobile app testing, access control, encryption, GDPR, credential rotation, and server log analysis. On Day 1, I can provide a clear access-gap list, then complete the manual review within five working days and document every test, change, rotated credential, identified risk, and recommendation in the final report. I'm an individual freelancer and can work in any time zone you prefer. Please contact me with the best time for you to have a quick chat. Looking forward to discussing more details.
$250 USD in 7 days
3.9
3.9

Hello, I have thoroughly reviewed your project requirements for the 5-day comprehensive security review of your website, backend, and iOS/Android apps. I understand the critical aspects that need to be addressed, such as testing Stripe integration, GDPR compliance, OWASP Top 10 vulnerabilities, and ensuring the security of personal data. With over 5 years of experience in PHP and web security, I am well-equipped to handle the manual testing and security assessment tasks outlined in your project description. My expertise also extends to identifying and mitigating security risks effectively. To get a better sense of my skills, please visit my portfolio: https://www.freelancer.pk/u/Aqsa4400 I would be delighted to discuss the project further with you. Please feel free to start the chat so we can delve into the specifics. Best regards, Aqsa Usman
$60 USD in 2 days
3.6
3.6

Hello, I understand you're seeking a developer to conduct a comprehensive security review of your website and mobile applications. Ensuring robust security measures and identifying potential vulnerabilities is crucial for your project's integrity. I have experience with PHP and web security, which are essential for assessing your applications and backend systems. My proficiency in MySQL also allows me to evaluate data storage practices and ensure secure database interactions during the audit process. - Conduct thorough security assessments of your website and mobile applications. - Identify vulnerabilities and recommend actionable improvements based on best practices. - Provide a detailed report summarizing findings and proposed solutions for enhanced security. Could you please specify the scope of the applications you want to include in the review? Additionally, any particular areas of concern that you would like me to focus on would be helpful. I am ready to start immediately and can further discuss the details through Freelancer messages. Best regards, Jordan Rafael
$85 USD in 2 days
3.2
3.2

★•══•★ Hi client ★•══•★ I can perform a structured security review across your website, backend, Stripe/payment flows, APIs, and iOS/Android apps, with the focus on finding real risks rather than simply running automated scanners. I’ll manually test authentication, authorization, SQL injection, XSS, CSRF, exposed endpoints, API/webhook security, payment flows, data protection, encryption, storage, and access controls. I’ll also review PHP/MySQL versions, logs, monitoring, and configuration where access is provided. From Day 1, I’ll document any missing access or credentials you need to handle, and any required key/secret rotation will be clearly recorded. No hidden accounts, backdoors, or unnecessary access will be created. You’ll receive a clear security report covering findings, evidence, severity, recommended fixes, and everything reviewed or changed. Would you like me to begin with an initial access and security checklist? Best regards, Rico
$100 USD in 7 days
3.2
3.2

KBH.NV, Denmark
Payment method verified
Member since Oct 29, 2020
$15-25 USD / hour
$750-1500 USD
$30-250 USD
$250-750 USD
$250-750 USD
$30-250 USD
₹600-1500 INR
$1500-3000 USD
$250-750 USD
₹1500-12500 INR
$30-250 USD
$10-30 USD
₹12500-37500 INR
$250-750 USD
₹1500-12500 INR
₹1500-12500 INR
₹750-1250 INR / hour
$10-11 USD
$250-750 USD
₹12500-37500 INR
$250-750 USD
$30-250 USD
$15-25 USD / hour
$8-15 USD / hour
₹1500-12500 INR