Skip to content
Halberd Security
Authorised testing only. We test only with the owner's written authorisation, so scope is agreed before testing begins. Unauthorised testing is also illegal under the Computer Fraud and Abuse Act.

Service

Web application penetration testing for products your customers log into

Web application penetration testing is a manual attempt to break the login, the permissions and the business logic of your app, the way a determined attacker would, but with your written permission and a report at the end.

  • Named tester before day one
  • One retest within 30 days
  • OWASP WSTG and NIST SP 800-115
Web application penetration testing: scope roles and urls, test by hand and report and retest

What web application penetration testing covers

A scanner finds the known patterns. However, the findings that matter in a real app are usually logic flaws: one customer reading another customer's invoices, a user promoting themselves to admin, or a discount applied twice. That is why web application penetration testing is mostly manual work by a senior tester.

We test the areas below on every engagement, and then we follow wherever the app leads us.

  • Authentication, session handling and password reset flows
  • Authorisation between users, tenants and roles
  • Input handling, including injection and file upload
  • Business logic, such as payments, approvals and limits
  • The APIs the front end calls, because that is where most data leaves

How we scope web application penetration testing

Scope decides the price, so we set it in writing before anything starts. First, we list the roles that exist, because every extra role multiplies the permission checks. Next, we agree the environments, ideally staging with production-like data. Finally, we confirm the out-of-scope items, such as third-party payment pages you do not own.

As a result, you receive a fixed fee for a defined set of roles and features, rather than an open-ended day rate.

Are you ready for web application penetration testing?

Tick what is already true. Each open item usually adds a step to scoping.

Your result appears here as you tick, so you can see what is still open.

How a manual test compares with an automated scan

Buyers often receive both offers and cannot tell them apart. So here is the plain difference.

Automated scanManual application test
FindsKnown signatures and missing headers.Logic flaws, broken access control and chained issues.
False positivesMany, left for you to sort.Each finding is reproduced by hand.
Auditor evidenceRarely enough on its own.Built to be read by SOC 2, ISO 27001 and PCI DSS auditors.
Hands-on timeHours of tool time.Three to five days for a narrow app, longer for a full scope.

What the web application penetration testing report contains

Every finding comes with the request we sent, the response we got and the exact steps to repeat it. In addition, each one carries a severity, the business impact in plain words, and a fix your developers can act on. The method follows the OWASP Web Security Testing Guide, so an auditor can see what was covered.

After you fix the issues, one retest inside 30 days confirms the fixes. Consequently, the final version can show closed findings, which is what a customer or auditor wants to see.

What changes the price of web application penetration testing

Our published range for this work is $5,000 to $30,000. Four things move a quote inside it: the number of user roles, the number of distinct features, whether an API is included, and whether you need the work in a fixed window. A small app with one role sits near the bottom. On the other hand, a multi-tenant platform with admin, manager and user roles sits much higher.

Web application penetration testing questions

How long does web application penetration testing take?

A narrow web app usually needs three to five days of hands-on testing, and a full scope five to ten. The report follows a few days later.

Will testing break production?

We prefer staging. If production is the only option, we agree safe limits in writing first, such as no destructive tests and no load testing.

Do you need our source code?

No, although access to it makes the work deeper. Without it we test as an outside user would.

Is a retest included in web application penetration testing?

Yes. One retest inside 30 days is included, so the final report can show which issues are closed.

Related guides

Get a written scope for web application penetration testing

Tell us the roles, the features and the deadline. We reply with a written scope and a fixed fee, and testing starts only after you sign the authorisation.

Get my estimate