
Closed
Posted
Paid on delivery
Security Audit – Website & iOS/Android Apps We are looking for a developer/security specialist to perform a 5-day security review and manual testing of our website, backend and iOS/Android apps. The work includes: * Review and test Stripe integration, API keys, webhooks, payments, refunds, chargebacks, MobilePay and Apple Pay. * Review GDPR/security of personal data, access control, encryption, storage and deletion. * Manual review based on OWASP Top 10, including SQL Injection, XSS, CSRF, authentication, authorization and exposed API endpoints. * Test iOS and Android apps, including installation, login, backend communication, payments and data. * Review server/app logs, monitoring, PHP and other system versions. * Identify and report security risks and provide recommendations. Important requirements: * All sensitive credentials must be reviewed and, where required, changed/rotated and secured, including API keys, secret keys, webhook secrets, passwords and database credentials. * On Day 1, the freelancer must identify and inform us of all credentials/services that he cannot access and that we need to change or provide access to ourselves. * Access will initially be provided to FTP via SSH, control panel and Stripe. If additional access is required, the freelancer must request it from us. * Everything done must be documented, including tests performed, changes made, credentials/keys rotated, issues found, files delivered and configurations reviewed. * No hidden accounts, backdoors or unauthorized access may be created or left behind. * A final written security report must be delivered. * 5 working days total, including any delays. * Fixed price: $175 USD, paid through Freelancer.com in 2 milestones. * 2 weeks of free support after final delivery and final milestone payment. * All files, credentials, source code and information are strictly confidential and may not be shared with anyone. * All access and copies of files must be removed when the cooperation e
Project ID: 40678137
90 proposals
Remote project
Active 2 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
90 freelancers are bidding on average $415 USD for this job

Hello, I have carefully reviewed your project description for a 5-day comprehensive security review of your website, backend, and iOS/Android apps. As a security specialist with extensive experience in conducting security audits, manual testing, and identifying vulnerabilities, I am confident in my ability to meet your requirements effectively. My approach will involve a thorough review and testing of the Stripe integration, API keys, webhooks, payments, refunds, chargebacks, as well as GDPR compliance and data security. I will conduct manual reviews based on OWASP Top 10 standards, ensuring protection against common threats like SQL Injection, XSS, CSRF, and more. Additionally, I will meticulously test your iOS and Android apps, review server logs, monitor system versions, and provide detailed security recommendations. I understand the critical importance of safeguarding sensitive credentials and ensuring the confidentiality of your data. Rest assured, all work will be meticulously documented, and I will provide a comprehensive security report upon completion. If you are interested in discussing further details or have any questions, please feel free to open a chat. I am here to provide initial insights and discuss the technical approach in more detail. Sincerely, Rajesh
$500 USD in 10 days
9.4
9.4

Hi Valuable Client, CnEL India can perform the 5-day comprehensive security review of your website, backend, and iOS/Android applications with a structured, documentation-first approach. **Our methodology:** 1. **Day 1 – Access & baseline audit:** Review all provided access, identify missing credentials/services, map the application architecture, APIs, integrations, and data flows. 2. **Application security testing:** Manually assess authentication, authorization, session handling, API exposure, SQL injection, XSS, CSRF and other OWASP Top 10 risks. 3. **Payment & integration review:** Examine Stripe, webhooks, API/secret keys, refunds, chargebacks, MobilePay and Apple Pay flows, including credential exposure and configuration risks. 4. **Mobile & infrastructure review:** Test iOS/Android communication, storage, authentication and payment flows, plus server versions, logs, monitoring and configurations. 5. **Remediation & documentation:** Record every finding with severity, evidence, impact and recommended remediation. Where authorized, secure configurations and rotate exposed credentials. 6. **Final validation:** Re-test critical findings and deliver a comprehensive security report covering tests performed, changes made and recommendations. We will maintain strict confidentiality and ensure no unauthorized accounts, backdoors or access mechanisms are introduced or retained.
$500 USD in 15 days
9.0
9.0

Hi — Elias here from Miami. I understand you're looking for a comprehensive security review for your website and mobile applications. The goal is to ensure robust security measures protect sensitive data and maintain system integrity. What usually matters most is identifying vulnerabilities across platforms. A common issue in systems like this is ensuring consistent security practices between web and app environments. The tricky part is integrating security protocols without disrupting user experience. My approach would involve a systematic audit of your architecture, focusing on areas like API security, data encryption, and user permissions. Establishing a solid baseline for security ensures compliance and maintainability for future enhancements. I've worked on similar security audits for various platforms, helping to balance functionality and security. This experience allows me to anticipate risks and tailor the audit process to your needs. A few questions to better understand the scope: Q1 – Are there specific compliance requirements you need to meet? Q2 – What primary user roles will interact with these systems? Q3 – Have you identified any areas of concern or prior incidents to focus on? Happy to discuss the details and suggest the best technical approach. Looking forward to hearing from you.
$500 USD in 2 days
8.4
8.4

As an experienced senior full-stack web and e-commerce developer with over a decade of expertise, I am uniquely suited to conduct a comprehensive security review of your website, backend, and mobile apps. Having worked on projects involving WordPress, WooCommerce and payment gateway integrations like Stripe and PayPal, I have a deep understanding of the need for robust security measures to protect sensitive data. Over the years, my work has centred around building scalable and secure systems. My knowledge in MySQL ensures that I can perform a thorough review of your databases and identify any security risks or vulnerabilities. Moreover, I have a keen eye for UI/UX design, which means in addition to checking for OWASP top 10 threats like SQL Injection and XSS, I can also streamline your user's experience by identifying any areas where their personal data is potentially at risk.
$500 USD in 7 days
8.2
8.2

A 5-day security review covering your website, backend, and iOS/Android apps requires a structured audit rather than automated scanning alone. I will begin on Day 1 by inventorying the provided SSH/FTP, control panel, Stripe, application, database, and monitoring access, then immediately identify any credentials or services you must provide or rotate yourselves. I will manually test the Stripe flow, API keys, webhook signing, payments, refunds, chargebacks, MobilePay, and Apple Pay, including authorization and replay-related risks. I will review the PHP/MySQL application and exposed endpoints against OWASP Top 10 concerns such as SQL injection, XSS, CSRF, authentication, authorization, insecure storage, encryption, and data deletion. The mobile review will cover installation, login, backend communication, payment handling, local data, tokens, and sensitive information exposure on both platforms. I will also inspect server and app logs, monitoring, configuration, and software versions. Any required key/password/webhook rotation will be documented, and I will leave no hidden accounts, backdoors, temporary access, or copied files. You will receive a final written report with severity, evidence, reproduction steps, remediation recommendations, a complete access/change log, and two weeks of post-delivery support. Muhammad Saad
$350 USD in 5 days
7.8
7.8

Hi, I can help you with "Perform 5-Day Comprehensive Security Review" as per your given project description. We can discuss more in detail during a chat conversation when you are available. I've worked on many PHP projects in recent times. So I am confident on achieving your expected Goals. Please initiate a communication thread to discuss further and start with the project. ⭐ 5.0/5 from a recent client: "A more professional version: “Excellent work! The job was completed within the committed timeline. Great quality, professionalism, and timely delivery. Highly appreciated and recommended.”" Final timeline and cost will be confirmed in chat after a complete understanding and documentation of the project expectations in detail.
$450 USD in 9 days
7.4
7.4

Hello, As a seasoned web developer with over 8 years of experience, I bring specialized skills and an in-depth understanding of the web development process to the table. My proficiency in MySQL, PHP and Web Security are particularly apt for a comprehensive security review project like yours. I have successfully carried out numerous security audits, always focusing on sensitivity, confidentiality and thorough documentation. My offerings go beyond addressing your project requirements diligently - as detailed in your description. They encompass a "big picture" approach, including assuring responsive and user-friendly websites, fast and secure solutions and strategies for better SEO results - all virtues that you'd inherently benefit from during this project. Ultimately, my goal is to contribute to the creation of a robust online presence for your brand by identifying risks, delivering insightful recommendations and providing reliable post-delivery support. Misunderstandings are known to fester when left unattended during project undertakings. With me, you can rest easy knowing that I make excellent communication a priority. Transparent information flow coupled with impeccable timekeeping will surely be apparent throughout our cooperation.I also treat every bit of information or credentials I work with as strictly confidential - just as required in your listing - so you don't have to worry about privacy breaches at any point. Thanks!
$600 USD in 4 days
7.6
7.6

Hello!, I am a US-based senior software engineer and I’d approach this 5-day security review like a real audit, not a checkbox task. The main risk is usually not one huge flaw, but a mix of smaller issues across the website, APIs, and mobile apps that can expose data or enable account abuse. I can help you find those weak points quickly and give you a clear, prioritized fix plan. My process: 1. Map the attack surface across web, API, iOS, and Android 2. Review auth, sessions, encryption, input validation, file handling, and access control 3. Test APIs and mobile flows for leaks, misconfigurations, and insecure endpoints 4. Validate findings with reproduction steps, severity, and practical remediation 5. Deliver a concise report so your team can fix the highest-risk issues first I’m very detail-focused and I pay attention to what usually gets missed: role-based access, hidden endpoints, debug traces, weak tokens, and mobile-side exposure. I’ve worked on secure SaaS systems, PHP/MySQL apps, API-heavy platforms, and mobile integrations, so I can move fast without being sloppy. Could you please clarify the following questions to help me better understand the project? 1. Do you want a black-box review only, or will source code/staging access be provided? 2. Are there specific areas you already suspect, such as auth, payments, file uploads, or admin access? 3.
$600 USD in 2 days
6.7
6.7

Hi, I see you're aiming for a comprehensive 5-day security audit covering your website and iOS/Android apps which involves both frontend and backend layers that need deep vulnerability scanning. Ensuring seamless security across different platforms often uncovers hidden flaws in API interactions or data storage patterns. At Smart Sols, we have 10+ years of experience with Laravel, native PHP, and cross-platform Flutter apps to spot and fix these vulnerabilities efficiently. What specific compliance standards or threats are you most concerned about for this audit? Let's discuss how we can secure your platforms thoroughly today.
$600 USD in 7 days
6.9
6.9

Hello!! Your application can undergo a comprehensive security audit to identify vulnerabilities, misconfigurations, weak access controls, and other risks, followed by a clear report with prioritized remediation recommendations. * What application, infrastructure, or cloud environment needs to be audited? * Do you already have a defined scope and authorized test environment? * Do you require only the audit report, or should identified issues also be fixed? The audit will include authentication and authorization review, API security checks, input validation, session management, access-control testing, dependency and configuration review, data-protection checks, logging and security-header analysis, and vulnerability assessment within the authorized scope. The findings will be documented with severity, affected areas, evidence where appropriate, recommended remediation, and a clear priority list. Any fixes can then be validated through a follow-up security check. Relevant application security, API, web development, cloud, and database projects have been completed before, with a focus on responsible testing and practical remediation rather than disruptive testing. Let us confirm the authorized scope and environment so the audit can be performed systematically and safely. Best regards Farhin B
$250 USD in 10 days
6.8
6.8

Securing payment flows like Stripe, MobilePay, and Apple Pay within a tight 5-day window requires systematic threat modeling, not just running automated scanners. For your PHP backend, webhooks, and mobile apps, my audit focuses on three critical vectors: • Validating state consistency across Stripe idempotency keys to prevent race conditions during chargebacks and refunds. • Enforcing strict OWASP-compliant JWT/session authorization and eliminating IDOR vulnerabilities on exposed endpoints. • Auditing local device storage, Keychain/Keystore encryption, and certificate pinning on both iOS and Android builds. With 15+ years architecting secure, high-scale full-stack systems, I ensure zero lingering credentials, complete webhook signature verification, and a rigorous compliance report. Let us discuss access provisioning for Day 1 so we can map out the milestones and begin immediately. Gaurav Panwar Senior Full-Stack & System Architect (15+ Yrs Exp)
$500 USD in 30 days
6.4
6.4

Hello! We can run a full security review and document the risks for your website and apps. 1. What should we prioritize first during the review? 2. Do you want us to include remediation recommendations as well? — About us We are dZENcode – a full-cycle IT company for digital product development: from design and programming to integrations and post-release support. We build projects from scratch and also work on existing solutions that need further development, improvements, or technical support. You can find detailed information about our services and rates on our official website: https://dzencode.com. Please review it – after that, we can discuss the details and agree on the next step. ⚠️ After clarifying all details, we will define the scope, the suitable cooperation format – task-based, outsourcing, or outstaffing – and the final cost. Projects are guaranteed to reach release with us: • 10+ years providing IT services; • 90+ in-house specialists; • 250+ public reviews since 2015; • We support products under SLA after launch; • We work under NDA and a company contract!
$500 USD in 7 days
6.7
6.7

Hi, I'm Denis, a developer with experience in security audits for web and mobile apps, specializing in vulnerability identification and data protection. Your project involves a 5-day security review of your website, backend, and mobile apps, covering API integrations, data handling, OWASP Top 10 testing, and credential management. I’ll begin by reviewing all access points, documenting any missing credentials or issues on Day 1, then proceed with manual testing of payment flows, authentication, data storage, and encryption practices. I’ll assess Stripe integration, webhooks, and third-party methods like MobilePay and Apple Pay for risks like injection attacks or unauthorized access. For mobile apps, I’ll inspect network requests, local storage, and backend communication to ensure no sensitive data leaks. Server logs and outdated dependencies (e.g., PHP versions) will also be reviewed. All findings will be documented with actionable recommendations, and credentials will be rotated as needed. Since access may be limited initially, I’ll request necessary permissions upfront to avoid delays. The final report will include tested scenarios, risks, fixes, and post-delivery support. A potential challenge is hidden API endpoints or rate limits. I’ll collaborate with you to adjust scope if needed to prevent system overload. I’m available to start immediately. Let’s discuss further. Thanks, Denis
$300 USD in 3 days
6.1
6.1

Hello There! I’m Md Toriqul Islam, an experienced full-stack developer with strong expertise in web/mobile security, APIs, Stripe integrations, authentication, databases, and secure application architecture. I have rich experience reviewing web applications and mobile APIs, identifying OWASP Top 10 risks, testing authentication/authorization, payment flows, exposed endpoints, data handling, and server configurations. I understand you need a thorough 5-day manual security review covering your website, backend, iOS/Android apps, Stripe/Apple Pay/MobilePay, GDPR-related data security, credentials, logs, and infrastructure. I’m skilled in OWASP testing, API security, PHP, databases, mobile/backend communication, Stripe webhooks, access control, encryption, and secure credential management. A few questions: 1) Will test/staging accounts and non-production test payment credentials be available for the audit? 2) Do you have a preferred OWASP testing scope or any known security concerns you want prioritized? 3) Will iOS/Android test builds and the required server/API access be provided on Day 1? I can document every test, finding, change, credential rotation, and configuration reviewed, then provide a clear final security report within 5 working days. Looking forward to hearing from you. Best regards, Md Toriqul Islam
$250 USD in 4 days
5.9
5.9

I can thoroughly review your website, backend, and mobile apps within 5 days, focusing on the critical areas you listed. I’ve done similar audits for payment platforms where I verified Stripe and Apple Pay setups, ensured API keys were secured, and handled GDPR compliance reviews. On day one, I’ll audit access and note any missing credentials so you can help provide them quickly. The review will cover OWASP Top 10 risks with manual testing of SQLi, XSS, and auth flows, plus a deep dive into your iOS/Android apps' communication and payment processes. I’ll also validate server logs, system versions, and monitor for vulnerabilities. To streamline testing, do you currently have automated security tools or logging dashboards in place? Also, are backups regularly verified to ensure quick recovery if an issue is found? I’ll document every test step, rotated credential, and configuration change without leaving any traces or backdoors. A detailed final report with prioritized fixes will be delivered, followed by 2 weeks of support. Ready to start as soon as you provide initial access and credentials.
$250 USD in 7 days
5.9
5.9

✋ Hi, the main concern here is that this is a full security review across several layers, not only a website scan. Payments, mobile apps, backend APIs, credentials, access control, server configuration and personal-data handling all need to be checked together. I’d start by mapping the environments and access available on Day 1, then separate testing into application security, payment flows, mobile/backend communication, infrastructure and credential review. Any credential rotation should be documented carefully so nothing breaks silently after the change. The final report should distinguish critical issues from lower-risk findings and clearly record what was tested, changed and still needs action. Do you already have a staging environment for active security testing, or must everything be performed against the live production systems?
$510 USD in 7 days
5.5
5.5

Hi, I can help you with this project. I have relevant experience with PHP, Web Security, Testing / QA, MySQL and can handle the work from development to testing and delivery. I've reviewed your requirements and can provide a clean, reliable, and responsive solution. Let's discuss the details and get started. Best, Arslan Shahid
$250 USD in 7 days
5.7
5.7

I've performed OWASP-based security reviews and credential audits for PHP/MySQL stacks before, so this is straightforward. I'll start with credential inventory on Day 1—flagging any inaccessible services immediately—and rotate all exposed keys (Stripe, webhooks, API secrets) during the review. Static and dynamic testing will cover the OWASP Top 10, with special focus on payment flows (Stripe, MobilePay, Apple Pay) and backend communication in iOS/Android apps. Server-side checks include log analysis, PHP version validation, and encryption/storage verification. Deliverables: concise risk report with remediation steps and rotated credentials list. I can start immediately. Thanks, Andrii.
$450 USD in 4 days
5.2
5.2

Hello Sir/ Mam I have checked Requirements As a seasoned developer with a wealth of Experience in Python , Automation, DevOps ,Web Application , Linux , Penetrating Testing , Network security , Web security , Software Testing , Network Administration, Volp , SIP , Telecom Sales , Docker . Nginx . I'm confident I can bring your virtual reality project to life. My track record as demonstrated in my 100% job completion and 5-star review rating showcases My ability to deliver exceptional results on time and with utmost quality I believe that my skill set makes me the ideal candidate for this project Please come on chat we will discuss more about this I will be waiting for your reply . Thank you !
$251 USD in 2 days
5.3
5.3

Hello, The most immediate risk is exposed or improperly scoped payment credentials and webhook endpoints that allow replay, refund, or chargeback manipulation and that leak PII via mobile clients or logs. I will prioritize Stripe integration, API keys, webhooks, MobilePay and Apple Pay flows, and any backend endpoints that accept payment-related input or return personal data. I have delivered secure payment and compliance work before, including a payroll API and a mission-critical tax filing system where I tightened key storage, restricted webhooks by signature verification, and reduced PII retention to meet regulatory requirements. That work required manual OWASP Top 10 testing, mobile app validation of backend communication, and a formal written security report with remediation steps. I will begin with a credentials and access inventory and threat-focused manual tests: validate Stripe API key scopes, confirm webhook signature verification, test for SQL Injection, XSS, CSRF, authentication/authorization flaws, and inspect mobile app network calls for insecure storage or unencrypted data. I will also review server/app logs, PHP and system versions, and document any GDPR-related personal data issues and deletion workflows. Deliverables: documented activities per day, Day 1 list of credentials/services needing access changes, findings mapped to OWASP Top 10, concrete remediation guidance, final written security report, and 2 weeks free support as requested. - Do you have a staging environment with representative data and valid payment test keys I can use on Day 1? - Who should I contact for immediate credential changes and emergency access during the 5-day review? Best, Thomas Beigbeder
$380 USD in 4 days
5.3
5.3

KBH.NV, Denmark
Payment method verified
Member since Oct 29, 2020
$250-750 USD
$250-750 USD
$30-250 USD
$250-750 USD
$750-1500 USD
₹100-150 INR / hour
$8-15 USD / hour
₹4000-8000 INR
$250-750 USD
$10-30 USD
$250-750 USD
₹1500-12500 INR
₹12500-37500 INR
₹750-1250 INR / hour
€250-750 EUR
₹12500-37500 INR
₹750-1250 INR / hour
₹100-400 INR / hour
€2-6 EUR / hour
$2-8 USD / hour
₹100-400 INR / hour
$10-11 USD
$30-250 USD
₹600-1500 INR
₹601-602 INR