Home / Services / Security audit / Authenticated Application Test

Authenticated Application TestSecurity audit

$329Report in 8 business days30-day cover

What this package is

Pro tests your site as someone who has already logged in, which is the one angle no automated scanner anywhere can cover for you.

Most of the weaknesses that genuinely cost a business money sit behind the login: an ordinary user reaching another customer's data, a payment flow that accepts an amount edited on the user's side, an upload field that will take anything at all. Those need a person trying it by hand.

I cover every page that matters rather than just the front one, and send a video walking through the findings in plain language, because a security report nobody can read is a security report nobody acts on.

See it working

Every page that matters, not just the front oneThe free scanner reads one address at a time, and only what is open to the public. The pages behind a login are where the customer data and the money actually live.
PathWhat it isBehind loginFound
/HomePublic1
/productsProduct listPublic0
/loginSign inPublic1
/account/ordersCustomer order historyBehind login2
/checkoutPayment pathBehind login1
/account/uploadSlip uploadBehind login1
/adminAdmin dashboardBehind login1

7 pages tested · 4 of them behind a login · 7 findings in total

The four pages behind a login are the ones a basic scan never reaches, and three of the four worst findings are there.

A worked example for example-shop.test, built for the demonstration and not any client's data.

The scanner and the basic report are part of this package too

This package is not only the authenticated testing. The whole external assessment from the basic package is included.

Open full screen in a new tab →

The scanner is free and open to anyone. It works entirely from the outside and never touches the inside of your site. What this package adds is the full report in the second tab, ranked by severity with a fix for each finding and a summary written twice, once for people and once for engineers, instead of showing three findings and locking the rest.

Both pages are live on this site rather than mock-ups. You can use them from inside the frame.

Everything you get

This list is the entire scope of the package. Nothing is hidden in a contract.

Not included in this package
  • Testing anything you cannot show me written permission for. I ask for it before every job, with no exceptions.
  • A promise that you will never be hacked again. Nobody can sell you that honestly. What I can do is close what I find and cut down the ways in.
  • Compliance sign-off. I work alone, I am not an audit firm, and I hold no security certificate, so I cannot certify you for SOC 2, ISO 27001, or PCI. I can tell you what would fail one.
  • Third-party costs such as an SSL certificate or a WAF. If you need one I tell you the price first, and that money does not come to me.
  • Cleaning up a site that has already been broken into. That is a different job. Send it over and I will quote it separately.

What I need from you before starting

Every question needs an answer, because these are the settings your system is built from. None of them can be skipped. If one is not settled yet, put down what you know today and we adjust it when work starts.

How the work runs

1

Send me the link

The URL on its own is enough to start. For the authenticated test I also need a throwaway test account.

2

Permission and scope in writing

Before I touch anything I need written confirmation from you that the site is yours. You also get a short contract in English covering scope, the delivery date, and who owns what I produce.

3

I test it

My own tools do the first pass, then I go through by hand for the things tools do not catch. You never get raw scanner output handed to you as a report.

4

Report, walkthrough, then 60 days of questions

You get the PDF, and from the authenticated test up, a video where I talk through it. After handover you can keep asking me questions for 60 days.

Paying and getting started

Full price of this package$329
  • Paid in full at order The price is fixed and the scope is written out. No numbers appear later.
  • Work starts as soon as it lands No call to book and no quote to wait for.
  • 30 days of cover after delivery Anything wrong with my work is fixed at no charge.

Bank transfer or PromptPay. A receipt is issued every time, and a stamped work contract if you want one.

How to reach you

Questions about this package

How different is this from Basic? Is the gap worth it?

Basic checks what is visible from outside. Deep checks what happens after logging in, which is where the expensive weaknesses live. If your site is a profile site with no accounts, Basic genuinely is enough. If there are logins, payments or customer data, Basic never sees the part that matters most.

Will real orders be created, or data damaged?

No. I use test accounts and the payment system's test mode. Where no test mode exists, I test only the steps that create nothing real and record in the report how far each area could be checked. I do not delete or alter your data while testing.

Why is there a video as well?

Because most security reports die from never being read to the end. A video shows you what I clicked and what happened, which conveys severity far better than prose, and you can forward it to your team without booking a meeting.

How long does it take?

The report lands within five working days, counted from when the authorisation and the test accounts are complete. If the site turns out much larger than described, I tell you how much longer it needs before starting rather than going quiet and delivering late.

If you find something serious mid-test, do you say so immediately?

Immediately, without waiting for the report. If I find a door being used right now, or customer data actively exposed, I call you that day with a way to close it temporarily, and write it up afterwards.

Often booked together

← Back to all three packages