I will be your application security consultant and review your code and architecture
Cybersecurity Expert, Full Stack Developer
Over deze dienst
Your code works. But would it survive someone actively trying to break it?
I review web applications the way an attacker reads them: looking for the logic flaw, the missing authorisation check, the secret sitting in the wrong place.
WHAT I REVIEW
Authentication and session handling
Authorisation and access control (IDOR, privilege escalation)
Input validation and injection paths (SQLi, XSS, SSRF)
Secrets, API keys and configuration
Dependencies and known CVEs
Architecture: trust boundaries, data flows, what your frontend is allowed to decide
Any stack, any language.
WHAT YOU GET
Findings ranked by severity, in plain English
The exact file and line, with why it matters
A concrete fix for each one, written for a developer
A prioritised action list: do now, do soon, safe to ignore
I CAN ALSO FIX IT
I am a full stack developer, not only an auditor. If you would rather not touch it yourself, I implement the fixes and hand them back as changes you approve. Just ask for a custom offer.
CREDENTIALS
OSCP (Offensive Security, 2019), CEH (EC-Council, 2023), CISSP (ISC2, 2024).
I only review code you own or are authorised to review. Message me before ordering to confirm scope.
Testapplicatie:
API
Ontwikkelingstechnologie:
JavaScript
•
Node.js
•
PHP
•
React
•
TypeScript
Apparaat:
PC
•
Mac
•
Linux
Mijn portfolio
Veelgestelde vragen
What do you actually look at?
Authentication, authorisation, input validation, secrets handling, dependencies and architecture. I read the code manually and use tooling only to catch what a human would miss. Every finding is verified before it reaches the report.
How do you deliver the findings?
A written report: each finding with severity, the exact file and line, why it matters, and a concrete fix. Plus a prioritised list so you know what to do first. Ask me and I will send an anonymised sample.
What languages and stacks do you cover?
Any stack. JavaScript, TypeScript, Node, React, Next.js, Python, PHP, Ruby, Go, Java, .NET, mobile, plus the infrastructure around them. Security flaws follow the same patterns everywhere, so the language is never the blocker.
Do you fix the code yourself?
These packages cover review and remediation guidance, written precisely enough for your team to apply. If you would rather I implement the fixes directly, message me and I will send a custom offer.
Will you review code that is not mine?
No. I only review code you own or are explicitly authorised to review, and I ask you to confirm this before I start. Any request outside that will be declined.
What are your qualifications?
OSCP from Offensive Security (2019), CEH from EC-Council (2023) and CISSP from ISC2 (2024). Alongside that I work as a full stack developer, which is what makes the remediation advice practical rather than theoretical.
