Skip to content
· 6 min read

Web application pentest: what you are actually buying

Buyers type web application pentest. Most product teams need an authorized review of the live UI, auth, and API — not a six-week red team.

Laptop on a dark desk showing an abstract application, printed notes, brass lamp
Article language

Showing original language

People search web application pentest when they have a live product and a board, a customer, or a gut that wants proof.

The phrase is overloaded. It now means a $400 scanner PDF, a two-week CREST circus, and the useful middle: someone authorized to sit in your app, try the obvious and the slightly less obvious, and write a report engineering can use this week.

Short answer: A web application pentest, for most product teams, is an authorized review of one live app. I sell that as a web application security review for $2,400, $1,200 to start. The report is due 48 hours after access works.

What a web application pentest should cover

Frontend, session, and the APIs the UI already calls.

That is the surface a real user — and a slightly more privileged one — can reach:

  • Login, SSO, reset, invite, and role checks
  • Tenant boundaries on multi-tenant products
  • Forms, uploads, exports, and downloads
  • Missing auth on an endpoint the page already uses
  • Object access that ignores whose record it is

Source-code audit, mobile binaries, phishing, and Active Directory are other buys.

What it should not include

Exploit payloads do not belong in a PDF you will email around. Neither do live credentials or client names. A redacted sample report shows the format before you pay.

The clock should start when login works, not when the first sales email lands.

When to buy a longer job instead

Wait if you need a CREST or PCI QSA stamp, a social-engineering exercise, or a letter written for procurement theater. Hire the firm that sells that letter.

Buy a timeboxed pass if you have one production or staging URL, you can grant a test user, and you want a ranked list this week.

The offer and the $1,200 / $1,200 split are on the security review page and the pricing page.

FAQ

What is a web application pentest? +

In buyer language it is an authorized test of a live web app: login, roles, pages a user can see, and the APIs behind them. A multi-week infrastructure red team is a different product.

How much does a web application pentest cost? +

Serious small-app quotes usually sit between $2,500 and $15,000. I sell one application for $2,400, with $1,200 to start.

How fast can it be delivered? +

A focused single-app review can be written in 48 hours after working access, with a 24–72 hour window on a tiny or unusually large surface.

Related operator notes

Keep reading

No-pressure first step

Not sure which one fits?
Get a free 20-min audit.

Bring one workflow you'd want automated. I'll tell you which deployment fits — and which doesn't — in twenty minutes. No pitch deck, no follow-up sequence. Useful even if you don't buy.

  • A real plan, not a sales call

    Which surface (Telegram, Discord, Slack, phone) fits your team, and which one doesn't.

  • Honest "don't buy this" if it applies

    If a $99/month SaaS solves it, I'll tell you which one and how.

  • A timeline + price range

    When I could deploy, what it'd cost, and what you'd own at the end.