Skip to product information
Web Application Pentest - Extended
€6.295,00
Fixed price. Fixed scope. No sales call. A manual, authenticated penetration test of one web application and its API, for teams with multiple user roles or a larger feature surface.
Scope included
- 1 web application (single primary domain) including its backend API
- Up to 4 user roles tested, including privilege-escalation between roles
- Up to 75 API endpoints / dynamic pages
- Estimated effort: 6 tester-days
What we test
- OWASP Top 10 and OWASP API Security Top 10
- Authentication, session management and access control (IDOR, horizontal/vertical escalation)
- Business-logic flaws specific to your application
- Input handling: injection, XSS, SSRF, file upload
Deliverables
- PDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)
- 1 free retest within 45 days of the final report: we verify your fixes and issue an updated report
- Letter of attestation you can share with auditors and customers
- Critical findings reported to you immediately, not at the end of the test
Not included
- Social engineering / phishing, denial-of-service, physical testing
- Mobile apps, infrastructure/network testing, source-code review
If we discover during kick-off that your application is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.