I will audit your web app for security vulnerabilities and fix them

S
sherzod_mit
S
sherzod_mit
Sherzod
Sommige informatie wordt in het Engels weergegeven.

Over deze dienst

Is your web app actually safe, or does it just seem fine because nothing has broken yet?


Most vulnerabilities do not show up until someone exploits them: a manipulated price at checkout, a forged JWT granting admin access, a stored XSS payload sitting quietly in a comment field. I find these before your users, or attackers, do.


What is included:

  • Manual code review focused on real attack surfaces: auth, payment logic, file uploads, user input handling
  • - Testing for price and parameter tampering, mass assignment, XSS, CSRF, JWT trust issues, IDOR, and injection
  • - A written report: what I found, how it can be exploited, and exactly how to fix it
  • - Optional: I fix the issues myself with regression tests, so the fix actually holds

Real examples of what I have caught and fixed:

  • Checkout logic trusting client-sent prices (could buy anything for $0.01)
  • - Admin panels gated only by a client-decoded JWT, bypassable by editing localStorage
  • - A rich-text editor rendering raw HTML from user posts (stored XSS)
  • - Signup endpoints saving every field from the request body (self-promote to admin)

I read your actual code and think like an attacker, not just run automated scanners.

Respecteer de rechten van derden

Let erop dat het tegen het beleid van Fiverr voor freelancers is om thema's, templates of andere elementen in het geleverde werk op te nemen die inbreuk maken op de rechten van derden of toepasselijke wetten. Lees er meer over in onze Gids voor verantwoorde digitale creatie.

Maak kennis met Sherzod

Sherzod

MERN Stack Developer React and Nodejs Expert

  • Afkomstig uitZuid-Korea
  • Lid sindsdec 2025
  • Talen

    Oezbeeks, Engels, Koreaans, Russisch
Full-stack developer (Node.js/NestJS, React/Next.js, .NET) who owns projects end-to-end -- database to AWS deployment. Currently building 3 production systems for a Korean company: an internal ERP with a live Google Play app, a construction QA platform, and an e-commerce site. In personal projects, I audit codebases for real vulnerabilities (price tampering, privilege escalation, stored XSS) and fix them with tests to prove it. I use AI tools (Claude Code, Codex) for speed, but own every architecture and security decision myself. Let's build something that works in production.

Mijn portfolio