#web-app
Operator notes filed under web-app — chronological, newest first.
48 hour security review: when the clock actually starts
A 48 hour security review is possible on one web app if access works. The clock starts at login, not at the first sales email or the card charge.
API security review: start with the calls the UI already makes
An API security review for a product team starts with the endpoints the page already calls — missing auth, object access, uploads, and exports.
Application security assessment: the usable version
An application security assessment should rank what a signed-in user can abuse. Here is the scoped version product teams can finish in a week.
Authentication security review: login is the product
An authentication security review looks at login, reset, invite, roles, and session — the work most web app buyers actually need.
Authorized web app review: why the permission email matters
An authorized web app review starts with written permission and a URL you own. That is what separates a professional review from reckless scanning.
Cheap penetration test: when the PDF is just a scanner
Sub-$1,000 full pentest quotes are usually a scanner PDF. Here is how a cheap penetration test differs from a human pass on auth and APIs.
IDOR in a web app review: the finding buyers actually mean
When buyers say IDOR they mean object access that ignores whose record it is. That check belongs in an authorized web app review.
Sample pentest report: what to demand before you send credentials
A sample pentest report should show severity bars, remediations, and restored state — with no client names and no exploit payloads.
SSO and Entra in a web app security review
Guest invites beat shared passwords. What to grant a tester on an Entra- or Google-fronted SaaS app without handing over the keys.
Web app pentest vs security review: which one you are buying
Buyers type pentest. Most product teams need an authorized 48-hour review of the live UI, auth, and API. When the longer CREST job is the right spend.
Web app security review cost in 2026: what $2,400 actually buys
Most small-app pentest quotes sit between $2,500 and $15,000. Here is what a 48-hour authorized web application security review should include — and what it should not.
Web application pentest: what you are actually buying
Buyers type web application pentest. Most product teams need an authorized review of the live UI, auth, and API — not a six-week red team.
What is a penetration test for a product team?
A penetration test is authorized hostile use of a system you own. For a SaaS app that usually means the live UI, auth, and API — not a Hollywood red team.