Web Application Penetration Test
Fixed project price from 7,000 €, no hourly billing
30 minutes, no preparation needed. You will receive a written offer within a few working days.
Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017.

Diese Seite ist auch auf Deutsch verfügbar.
A Web Application Penetration Test is a manual security assessment of a web application and its APIs, focused on the OWASP Top 10: broken access control, injection, authentication flaws, and business logic vulnerabilities.
Your web application is reachable from the internet around the clock, for your customers and for attackers alike. A single access control flaw is often enough to expose other users’ data or take over the server. Those are exactly the flaws I find, before someone exploits them.
Scope
Web applications are tested against the most critical vulnerability classes, with a focus on the OWASP Top 10. This includes:
- Access control testing: broken access control, privilege escalation, IDOR (accessing other users’ data by changing an ID in a request)
- Authentication and session flaws: weak password reset flows, session fixation, JWT misconfiguration
- Injection attacks: SQL injection, command injection, SSTI
- Server-side request forgery (SSRF) and insecure deserialization
- Business logic vulnerabilities: flaws in the application’s workflow that automated scanners cannot detect, such as skipping a payment or approval step
- Misconfigurations: security headers, TLS settings, error disclosure
- Review of third-party components: outdated libraries, known CVEs
- Implementation of Defense-in-Depth measures
Android mobile app testing is also available on request.
The specific test procedure and tested components will be discussed in a Scoping meeting.
Why
- Automated scanners catch the obvious issues; access control and business logic flaws (the ones that actually lead to data breaches) require a human tester
- A single IDOR or broken access control bug can expose your entire customer database
- Web applications change constantly. A test is a snapshot of security at a point in time, and regular testing catches regressions introduced by new features
Why VidraSec 🦦
Martin Grottenthaler, Founder and Lead Penetration Tester. OSCP, CISSP, GCFA, GWAPT. Pentesting since 2017. More about me
In most web application tests I find at least one access control flaw that exposes other users’ data, exactly the kind of vulnerability automated scanners cannot detect. Manual testing means I actually understand the application’s logic instead of relying on scanner signatures. And for this type of testing I hold a dedicated certification: the GWAPT (GIAC Web Application Penetration Tester).
Typical Duration
3 to 5 days of testing (depends on the size and complexity of the application). Reporting takes roughly 30 to 50% of the test time on top.
Typical Price
from 7,000 €
The final price depends on the scope and is calculated from the planned effort, which the offer itemizes transparently (person-days times daily rate). The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same.
Not sure whether this fits your environment? In a free 30-minute call you get an honest assessment.
Deliverables
Every engagement includes:
- Written findings report with all vulnerabilities, prioritized by severity, with remediation steps
- Management summary tailored to your audience (technical or executive)
- Live debriefing to walk through findings and answer questions
- Retesting after remediation available on request
See example reports for what a VidraSec report looks like.
Compliance
Relevant for GDPR (protection of customer data processed by the application), NIS2 (Article 21 covers the security of all network and information systems, including web applications), and ISO 27001. For financial-sector companies, DORA additionally requires regular security testing of critical applications.
Frequently asked questions
Is the test manual or automated?
It is primarily manual. Automated scanning supports the work, but the depth, and especially access control and business logic vulnerabilities, comes from manual testing by an experienced tester. Reports do not include automated scanner noise.Do you test APIs and mobile apps as well?
Yes. REST and GraphQL APIs are in scope, and Android mobile app testing is available on request. The exact components are agreed in the scoping meeting.Does the test require credentials or source code?
Most engagements are greybox, using valid user accounts to reach the parts of the application where the interesting vulnerabilities live. Source code is not required, though it can be included for a deeper review.How long does a web application penetration test take?
Typically 3 to 5 days of testing, depending on the size and complexity of the application, plus roughly 30 to 50 percent of that time for reporting.How much does a web application penetration test cost?
From 7,000 euros. The final price depends on the size and complexity of the application and is calculated individually based on the required effort.How does the fixed price work?
The offer itemizes the planned effort transparently (person-days times daily rate), so you see exactly how the price is calculated. The offer total is the final price: if the actual effort ends up a little over or under the estimate, the price stays the same, and you always receive the full agreed deliverables.More questions on pricing, lead times, NDAs, or compliance: see the general FAQ

