I will perform a professional web application security audit
Full Stack Developer Development and Security Audits
Acerca de este Servicio
I will perform a professional security and technical audit of your web application, focusing on identifying real vulnerabilities, security risks and architectural issues before production.
### Technologies I work with
JavaScript / TypeScript
React / Next.js
Node.js / Express / Fastify
Python / FastAPI / Django / DRF
MongoDB / PostgreSQL
REST APIs
WebSockets
JWT authentication
Redis
Docker and deployment configurations
### What I can audit
Frontend and backend security
API security and access control
Authentication and authorization
IDOR and data exposure
Business-logic vulnerabilities
Database security
Dependency vulnerabilities
CORS and security configuration
Git history and exposed secrets
Production-readiness and architecture
You will receive a structured PDF report containing confirmed findings, severity levels, affected components, potential impact and technical recommendations.
I combine manual source-code analysis with targeted security testing rather than relying only on automated scanners.
For large or complex applications, please contact me before ordering so I can define the appropriate scope, timeline and price.
Tecnología de desarrollo:
Otros
Mi porfolio
FAQ
Do you manually review the code?
Yes. I manually review the source code and combine it with targeted security testing and automated analysis where appropriate.
What technologies can you audit ?
I primarily work with React, Next.js, JavaScript/TypeScript, Node.js, Express, Fastify, Python, FastAPI, Django, Django REST Framework, MongoDB, PostgreSQL, Redis, REST APIs, WebSockets, JWT and Docker-based applications.
Do you provide a report?
Yes. You receive a structured PDF report containing findings, severity, impact, affected components and technical recommendations.
Do you fix vulnerabilities?
The audit focuses on identification and recommendations. Fixes can be quoted separately after the audit.
Can you audit a production application?
Yes, provided that the appropriate authorization and testing scope are agreed beforehand.

