# Web Application Security Assessment

> From $8K · Offensive Security · https://cisomarketplace.services/services/web-application-security-assessment

In-depth testing of web applications for security vulnerabilities

## In scope

- Authenticated testing by user role against OWASP ASVS and the OWASP Top 10
- Authentication, session management and access-control testing
- Input handling and injection testing
- Business-logic abuse cases
- API endpoints used by the application
- Configuration, headers and transport security review

## Deliverables

- Web application security report with reproducible findings
- Risk-rated findings mapped to OWASP ASVS
- Developer remediation guidance
- Executive summary
- Retest of fixed findings

## Tiers

### Basic Web App Assessment: $8K

Grey-box penetration test of 1 web application with up to 2 user roles: authenticated and unauthenticated testing against common web vulnerability classes, manual validation of findings. No separate API testing. One retest.

Limits: web apps 1

Includes:
- 1 web application, up to 2 user roles
- Authenticated and unauthenticated testing
- Manual validation of scanner findings
- Vulnerability report with fixes
- One retest of fixed findings

Excludes:
- Dedicated API testing
- Source code review
- More than 2 user roles
- Ongoing scanning after the test

### Advanced Web App Assessment: $15K

Penetration test of 1 web application with up to 5 user roles plus 1 API (up to 50 endpoints): business logic and access-control testing across roles, API authz testing, dependency analysis. One retest.

Limits: web apps 1, apis 1

Includes:
- 1 web application, up to 5 user roles
- 1 API, up to 50 endpoints
- Business logic and cross-role access control testing
- Dependency analysis
- One retest of fixed findings

Excludes:
- Additional applications
- Ongoing scanning after the test
- Source code review
- CI/CD SAST/DAST integration

### Premium Web App Assessment: $25K

Full-scope web application testing with continuous monitoring

Limits: web apps 2, apis 3

Excludes:
- Full manual re-test each month
- Mobile app testing
- Fixing the code
- Infrastructure/network penetration testing

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=web-application-security-assessment
