Web & Mobile App Security Audit
Web & Mobile App Security Audit
Web & Mobile App Security Audit
Web & Mobile App Security Audit
Web & Mobile App Security Audit
Web & Mobile App Security Audit
Web & Mobile App Security Audit

Web & Mobile App Security Audit

Client: Freelancer.com|Web Applications

PROJECT SUMMARY

Performed a full security audit and functional testing of a client's website, backend, and iOS/Android apps covering Stripe payment security, personal data protection, OWASP vulnerabilities, and system log monitoring.

The Challenge

The client needed a full security review of their live website, backend, and iOS/Android apps covering Stripe payments, personal data protection, OWASP vulnerabilities, and system monitoring.

The Solution

Performed a hands-on security audit and functional testing using Stripe API, PHP, MySQL, REST APIs, and Postman: 1)Stripe Payment Integration i) Tested API keys & webhooks ii) Verified end-to-end payment flow iii) Checked refunds & chargebacks iv) Enabled MobilePay & Apple Pay v) Rotated all keys & secrets 2)Personal Data Protection i) Verified PII encryption ii) Reviewed access control iii) Checked retention & deletion process 3)OWASP Top 10 Testing i) Checked SQLi, XSS, CSRF ii) Reviewed auth & exposed endpoints iii) Tested input/session handling 4)iOS/Android App Testing i) Tested apps with new keys ii) Verified login, payment, data display iii) Checked API requests/responses 5)Log Monitoring & Updates i) Reviewed logs & security events ii) Checked PHP/system updates

The Results

i) Secured, fully rotated Stripe setup ii) Verified encrypted, access-controlled personal data iii) Identified & prioritized OWASP risks iv) Confirmed apps work securely with new keys v) Improved log monitoring & flagged outdated components vi) Delivered full security report with findings & recommendations

Technology stack

CyberSecuritySecurityAuditStripeIntegrationOWASPSQLInjectionApplePay

Like what you see?

Explore more projects like this one across the full portfolio.