Web Application Pentest - Extended

Web Application Pentest - Extended

€6.295,00
Skip to product information
Web Application Pentest - Extended

Web Application Pentest - Extended

€6.295,00

Fixed price. Fixed scope. No sales call. A manual, authenticated penetration test of one web application and its API, for teams with multiple user roles or a larger feature surface.

Scope included

  • 1 web application (single primary domain) including its backend API
  • Up to 4 user roles tested, including privilege-escalation between roles
  • Up to 75 API endpoints / dynamic pages
  • Estimated effort: 6 tester-days

What we test

  • OWASP Top 10 and OWASP API Security Top 10
  • Authentication, session management and access control (IDOR, horizontal/vertical escalation)
  • Business-logic flaws specific to your application
  • Input handling: injection, XSS, SSRF, file upload

Deliverables

  • PDF report with executive summary and technical findings (CVSS-scored, with reproduction steps and remediation advice)
  • 1 free retest within 45 days of the final report: we verify your fixes and issue an updated report
  • Letter of attestation you can share with auditors and customers
  • Critical findings reported to you immediately, not at the end of the test

Not included

  • Social engineering / phishing, denial-of-service, physical testing
  • Mobile apps, infrastructure/network testing, source-code review

If we discover during kick-off that your application is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.

You may also like