Web application pentest: what you are actually buying
Buyers type web application pentest. Most product teams need an authorized review of the live UI, auth, and API — not a six-week red team.
People search web application pentest when they have a live product and a board, a customer, or a gut that wants proof.
The phrase is overloaded. It now means a $400 scanner PDF, a two-week CREST circus, and the useful middle: someone authorized to sit in your app, try the obvious and the slightly less obvious, and write a report engineering can use this week.
Short answer: A web application pentest, for most product teams, is an authorized review of one live app. I sell that as a web application security review for $2,400, $1,200 to start. The report is due 48 hours after access works.
What a web application pentest should cover
Frontend, session, and the APIs the UI already calls.
That is the surface a real user — and a slightly more privileged one — can reach:
- Login, SSO, reset, invite, and role checks
- Tenant boundaries on multi-tenant products
- Forms, uploads, exports, and downloads
- Missing auth on an endpoint the page already uses
- Object access that ignores whose record it is
Source-code audit, mobile binaries, phishing, and Active Directory are other buys.
What it should not include
Exploit payloads do not belong in a PDF you will email around. Neither do live credentials or client names. A redacted sample report shows the format before you pay.
The clock should start when login works, not when the first sales email lands.
When to buy a longer job instead
Wait if you need a CREST or PCI QSA stamp, a social-engineering exercise, or a letter written for procurement theater. Hire the firm that sells that letter.
Buy a timeboxed pass if you have one production or staging URL, you can grant a test user, and you want a ranked list this week.
The offer and the $1,200 / $1,200 split are on the security review page and the pricing page.
FAQ
What is a web application pentest? +
In buyer language it is an authorized test of a live web app: login, roles, pages a user can see, and the APIs behind them. A multi-week infrastructure red team is a different product.
How much does a web application pentest cost? +
Serious small-app quotes usually sit between $2,500 and $15,000. I sell one application for $2,400, with $1,200 to start.
How fast can it be delivered? +
A focused single-app review can be written in 48 hours after working access, with a 24–72 hour window on a tiny or unusually large surface.