What does a web application penetration test cover?
We test the things that actually get applications breached: broken access control and insecure direct object references, injection flaws such as SQL injection, authentication and session management weaknesses, cross-site scripting, server-side request forgery, insecure file upload, security misconfiguration, and business-logic flaws a scanner cannot understand. The work is guided by the OWASP Top 10 and the OWASP Web Security Testing Guide, so nothing important is skipped.
Do you follow a recognised methodology?
Yes. Web application testing follows an OWASP-aligned methodology, built around the OWASP Web Security Testing Guide and the OWASP Top 10, and API testing follows the OWASP API Security Top 10. Automated tooling is used for breadth, but the findings that matter come from manual testing by an experienced tester.
Do you test authenticated areas and different user roles?
Yes, and this is where the most serious issues usually live. We test as different user roles to find broken access control, horizontal and vertical privilege escalation, and data that one user can reach when they should not. Give us a set of test accounts covering each role and we will exercise the boundaries between them.
Do you test APIs as well?
Yes. REST and GraphQL APIs are tested against the OWASP API Security Top 10, covering broken object-level authorisation, broken authentication, excessive data exposure, and rate-limiting and resource issues. API testing can form part of the same engagement as the web application it supports, or stand on its own.
Will testing disrupt our live application?
We agree the rules of engagement in writing before any testing begins. Where possible we test a staging environment that mirrors production; where production must be used, we schedule around your quiet periods, avoid genuinely destructive actions, and stay in contact throughout so there are no surprises.
What do we get at the end?
A clear report written to be read by both your board and your developers: an executive summary, then each finding with a risk rating, the evidence, step-by-step reproduction, and specific remediation advice. We talk you through it if that helps, and once you have fixed the issues we retest to confirm the fixes hold, at no extra cost.
How is this different from an automated vulnerability scan?
A scanner is fast and good at breadth, catching known issues and missing patches. It cannot tell you whether a flaw is genuinely exploitable, chain several small issues into a real breach, or reason about your application's business logic and authorisation model. A penetration test combines the tooling with a skilled tester doing exactly that, and validates findings so you are not chasing false positives.
How much does a web application penetration test cost?
There is no fixed public price, because it depends on scope: the size of the application, how many user roles and authenticated areas are involved, and whether APIs are in play. Tell us about your application on a short scoping call and we will come back with a fixed-price quote, typically within 48 hours.