
In Progress
Posted
I’m looking for a seasoned security professional to run a deep-dive audit across both the frontend and backend of my online marketplace. My main concern is tightening anything that touches user authentication (currently session-based) and the way we store data— from database configuration through to file uploads and logs. Here’s what I need from you: • A penetration-style assessment of the live site and its APIs, using common tools such as OWASP ZAP or Burp Suite alongside manual exploration. • A code-level review that zeroes in on the session-handling logic, cookie flags, CSRF protections, and any spots where sensitive data might inadvertently be logged or cached. • Database and storage inspection to confirm encryption at rest, least-privilege access, and safe backup practices. • A concise report summarising every discovered issue, ranked by severity, with practical remediation steps I can hand straight to my dev team. Acceptance criteria • Every critical or high-risk finding clearly documented with a reproducible proof-of-concept. • Actionable fixes for medium-risk issues or clear justification when no change is required. • A final walkthrough call to verify corrections and answer questions. While payment workflows exist, they’re already handled by a third-party provider and are not the primary focus right now— but if you spot related weaknesses as you work, flag them. Let’s make sure our user sessions stay locked down and our data stays private.
Project ID: 40674475
14 proposals
Remote project
Active 5 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

You need an evidence-based review of session security and data handling across browser, API, application code, database, uploads, logs, and backups—not a scanner export filled with false positives. I have 9+ years of full-stack experience building and reviewing authenticated, database-driven production systems. I would define an authorised test scope first, then combine OWASP ZAP or Burp Suite with manual session, CSRF, cookie, access-control, upload, caching, logging, and API tests. The code review would trace session creation, rotation, expiry, invalidation, privilege changes, and sensitive-data paths. Findings would be reproduced safely, mapped to severity and affected components, and delivered with concrete fixes and retest results. I should be transparent that my primary background is secure software engineering rather than dedicated red-team consulting. Is a staging environment and source-code access available for testing?
₹4,000 INR in 7 days
2.3
2.3
14 freelancers are bidding on average ₹1,143 INR/hour for this job

Hello, I can help you with "Full-Stack Marketplace Security Audit" as per your given project description. We can discuss more in detail during a chat conversation when you are available. I've worked on many PHP projects in recent times. So I am confident on achieving your expected Goals. Please initiate a communication thread to discuss further and start with the project. ⭐ 5.0/5 from a recent client: "A more professional version: “Excellent work! The job was completed within the committed timeline. Great quality, professionalism, and timely delivery. Highly appreciated and recommended.”" Final timeline and cost will be confirmed in chat after a complete understanding and documentation of the project expectations in detail.
₹750 INR in 1 day
5.6
5.6

I’d approach this as an authentication + data exposure audit first, not just an automated vulnerability scan. I’ll test the live application and APIs with Burp Suite/ZAP, then manually trace session handling, cookies, CSRF, authorization boundaries, uploads, database access, backups, caching, and logging to find issues scanners commonly miss. My approach: Map the authenticated/unauthenticated attack surface and API endpoints. Test session fixation/hijacking, cookie flags, logout/session invalidation, CSRF, IDOR/access-control issues and common OWASP risks. Review the relevant code for session/authentication logic and sensitive data exposure. Check file-upload handling, storage permissions, database privileges/encryption, backups and application/server logs. Document each finding with severity, impact, reproduction steps/PoC and a practical developer-ready fix. I’ll keep the report concise and prioritized, with special attention to anything that could expose user accounts or private marketplace data. I’ll also flag payment-related weaknesses if encountered, without expanding the scope unnecessarily. One question: can you provide access to the application source code and a dedicated test account/role set for the live environment?
₹1,000 INR in 40 days
2.4
2.4

Hi, I've reviewed your project, "Full-Stack Marketplace Security Audit", and I understand what you're looking to achieve. Based on the requirements in your project description, my Web Security, Computer Security, MySQL, Database Administration, Internet Security, Penetration Testing, API Testing, Security Auditing experience aligns well with the work you need. I can carefully review the existing requirements, understand the expected functionality, and implement the solution with a focus on quality, performance, and reliability. Project Requirements: I’m looking for a seasoned security professional to run a deep-dive audit across both the frontend and backend of my online marketplace. My main concern is tightening anything that touches user authentication (currently session-based) and the way we store data— from database configuration through to file uploads and logs. Here’s what I need from you: • A penetration-style assessment of the live site and its APIs, using common tools such as OWASP ZAP or Burp Suite alongside manual exploration. • A code-level review that zeroes in on the session-handling logic, cookie flags, CSRF protections, I’ll make sure the work is handled professionally, with clear communication throughout the project and attention to the details mentioned in your requirements. I’m ready to discuss the project and get started. Best Regards, Khadija Tul Kubra
₹1,000 INR in 7 days
0.0
0.0

Hi, I can help audit your marketplace from both the application and API side, with particular focus on authentication, session management, data protection, and secure storage. I’d combine manual security testing with tools such as OWASP ZAP/Burp Suite to assess the live application and APIs. I’ll specifically review: • Session handling, cookies and security flags • CSRF protection and authentication flows • API authorization and access-control issues • Sensitive data exposure through logs, cache, responses or errors • File-upload security and validation • Database permissions and configuration • Encryption, backups and storage practices • Common OWASP vulnerabilities and misconfigurations For every finding, I’ll provide severity, affected component, reproduction steps/PoC where appropriate, business impact, and practical remediation guidance your development team can act on. After fixes are implemented, I can perform a focused retest to verify the critical/high-risk issues are properly resolved and walk your team through the findings. I have a QA background with hands-on experience in API testing, Postman, JIRA and web application testing, and I’m comfortable working through technical issues systematically. I’m available to start promptly and can begin with the authentication/session and API surface before moving into storage and code-level review.
₹750 INR in 30 days
0.0
0.0

We have over 5 years experience with similar projects for online marketplaces. You're looking to enhance user authentication security and improve data storage practices to protect sensitive information. To approach this audit, I will conduct a thorough penetration assessment of both the frontend and backend, utilizing tools like OWASP ZAP and Burp Suite, complemented by manual testing. I will perform a detailed code review to identify vulnerabilities in session handling, cookie flags, and CSRF protections. Additionally, I'll inspect your database and storage configurations to ensure encryption and access controls are properly implemented. Deliverables: - Comprehensive penetration report with identified vulnerabilities - Code-level review focusing on session management and data security - Database and storage configuration assessment - Actionable remediation steps for each issue - Final walkthrough call to discuss findings and corrections I am happy to share relevant examples of my work. Let’s discuss how I can help secure your marketplace effectively. Regards, RyanF172
₹750 INR in 7 days
0.0
0.0

Hello, I can support Full-Stack Marketplace Security Audit with a defensive, evidence-driven security approach. My experience covers secure SaaS architecture, access control, API abuse analysis, intrusion and anomaly validation, audit trails, Linux/cloud environments, and clear technical reporting. I would begin by confirming scope, authorization, assets, and success criteria, then execute the agreed assessment or implementation with reproducible findings, prioritized remediation, and a concise handover. I do not rely on generic scanner output; each result is verified and tied to an actionable fix. Please share the authorized scope and expected deliverables so I can confirm the first milestone.
₹1,000 INR in 40 days
0.0
0.0

We've just completed a similar project, helping a small marketplace enhance its security posture through a comprehensive audit. Based on what you're looking for, I can perform a deep-dive assessment of both the frontend and backend of your site, ensuring that user authentication and data storage are tightly secured. I specialize in penetration-style assessments and code reviews, utilizing tools like OWASP ZAP and Burp Suite, alongside thorough manual exploration. My approach focuses on session-handling logic, cookie flags, and CSRF protections, as well as database and storage inspections for encryption and access control. With 75+ 5-star reviews on similar projects and a top 1 percent ranking among 75 million users, I can provide a concise report summarizing every finding, ranked by severity, with actionable remediation steps. I'd love to discuss how we can enhance your marketplace's security further. Regards, Ruan111.
₹750 INR in 7 days
0.0
0.0

I’m Rakhshan and I am incredibly well-suited for your Full-Stack Marketplace Security Audit project. With a Bachelor’s degree in Computer Science, a PhD in Artificial Intelligence, and nearly 20 years of experience across academia and software engineering, I bring a wealth of knowledge and expertise to the table. From my role as Chief Technology Officer at an AI startup to my proficiency in designing highly secure database architectures, all the skills you listed are within my wheelhouse. One of your specifications is a code-level review which aligns perfectly with my significant expertise in backend development. My proficiency with MySQL means that not only can I inspect your database to confirm encryption at rest but also use the least-privilege access possible for the deep-dive audit. Additionally, owning to my cloud deployment experience and scalable architecture knowledge, I will ensure safe backup practices as well.
₹750 INR in 40 days
0.0
0.0

Hi, The findings that matter here probably won't be the cookie flags — those are an afternoon's fix. With session-based auth on a marketplace it's usually session lifecycle and multi-actor authorization: sessions surviving a password reset, no rotation on privilege change, and buyer/seller endpoints where swapping an ID returns someone else's orders. And if seller uploads are served from the app's own origin, a stored XSS becomes session theft — exactly what you're trying to prevent. I've run this kind of engagement on a couple of marketplaces. The ugliest finding wasn't in the app at all — a payment webhook accepting unsigned callbacks. Worth a look even though payments aren't the focus. From what I gathered, you want something your devs can act on Monday, not a 90-page scanner dump. I'd time-box the ZAP/Burp pass early and spend most of the hours on manual auth and access-control testing, where scanners are weakest. I'd need written authorization and either staging or a defined test window before starting. Happy to jump on a call to scope it.
₹1,000 INR in 40 days
0.0
0.0

I have 2 years of experience with bug bounty and web application pen-testing workflows and worked with nearly 13 companies in their bug bounty programs with more than 80% completion rate. I'll provide a professional report and service.
₹1,500 INR in 40 days
0.0
0.0

Chennai, India
Member since Aug 27, 2026
₹12500-37500 INR
₹600-1500 INR
$10-15 CAD
$15-25 USD / hour
₹12500-37500 INR
$25-50 USD / hour
₹750-1000 INR / hour
₹750-1250 INR / hour
₹75000-150000 INR
$15-25 USD / hour
$30-250 USD
₹600-1000 INR
₹600-1500 INR
$250-750 USD
₹1500-12500 INR
$30-250 CAD
₹750-1250 INR / hour
$30-250 USD
₹250000-500000 INR
$15-25 USD / hour