I've been a developer for 8 years and I'm moving into security testing. To build my portfolio, I want to test 5 side projects for free and give you a proper security report. Side projects are interesting to me because they usually ship fast with less security review. That's not a criticism, that's just how it works when you're building alone or in a small team. But if you have users, you probably want to know where the gaps are. Here's what I test: authentication flows, access control (can user A see user B's data?), API endpoints, input handling, session management, file uploads, business logic, and anything else your app exposes. If something is exploitable, I exploit it and document exactly how. You get a report with every finding, how serious it is, how I did it, and how to fix it. Not a scanner dump. Requirements: written permission before I touch anything (we agree on scope together). All I ask in return is feedback. If your project has auth, payments, user accounts, or any kind of sensitive data, that's exactly what I'm looking for. 48-hour turnaround. Comment or DM. First 5 people.   submitted by   /u/Exposethewealth [link]   [comments]