Web Application Security
Web Application Penetration Testing. No Vulnerability Undetected.
OWASP Top 10:2021, API Security, Business Logic - OSWA-certified experts find what automated scanners miss. Fixed-price quote in 24h.
Trusted by our clients
- 500+
- Web App Pentests Completed
- 94%
- of applications with vulnerabilities (OWASP 2021)
- 24h
- to Fixed-Price Quote
- 100%
- manually verified findings
OWASP Top 10:2021
We test all critical vulnerability classes
The OWASP Top 10 standard defines the most common and critical security risks in web applications. Our test covers all ten categories fully - every finding manually verified, no noise in the report.
Broken Access Control
We test authorization checks at all levels: horizontal and vertical privilege escalation, IDOR, misconfigured CORS, and missing access control on API endpoints.
Cryptographic Failures
We analyze TLS configuration, encryption of sensitive data (at rest and in transit), weak algorithms, flawed key generation, and insecure password storage.
Injection
SQL, NoSQL, OS, LDAP, and XPath injection. All input parameters tested for missing validation and parameterization - in forms, API parameters, and HTTP headers.
Insecure Design
We analyze architectural decisions for missing security controls: insecure password reset flows, missing rate limiting, and weak tenant separation.
Security Misconfiguration
HTTP security headers, cloud storage permissions, debug mode in production, unnecessary features, and default credentials. We systematically review the entire server configuration.
Vulnerable Components
We inventory all libraries, frameworks, and components used and cross-reference against known CVEs - including transitive dependencies in frontend and backend.
Auth Failures
Session management, brute force protection, secure token generation, MFA bypass, credential stuffing, flawed logout implementation, and JWT security are fully tested.
Software & Data Integrity
Deserialization vulnerabilities, insecure CI/CD pipelines, missing code signing, and supply chain risks in dependencies. We also test update mechanisms for tampering.
Logging Failures
We verify that security-relevant events (failed logins, access attempts on sensitive data) are logged and that logs are protected against tampering. SIEM integration is evaluated.
SSRF
Server-Side Request Forgery: We test whether attackers can force the server to make requests to internal services, metadata endpoints (AWS IMDS), or other internal systems.
All ten categories are tested manually - no automated scanning. Request a sample report
Methodology
Black-Box, Grey-Box, or White-Box?
Each pentest approach simulates a different attacker perspective. We advise you on which approach delivers the most value for your specific use case.
Black-Box Test
No prior knowledge, no access - our testers start like an external attacker from the internet. We conduct full reconnaissance and attempt to gain access independently.
Best suited for:
- Realistic attacker simulation
- External attack surface assessment
- Compliance evidence (PCI DSS)
Recommended
Grey-Box Test
We receive test credentials and basic application architecture information. This enables more efficient, deeper analysis - with the best balance of coverage and cost.
Best suited for:
- Maximum coverage within budget
- Testing authenticated features
- NIS-2 and GDPR Article 32
White-Box Test
Full access to source code, architecture documentation, and configurations. Enables the deepest analysis including code review, logic flaws, and configuration-based vulnerabilities.
Best suited for:
- Deepest vulnerability coverage
- Critical custom-developed systems
- Combined secure code review
API Pentest
Targeted Testing of REST and GraphQL APIs
Modern web applications are API-first. Many security vulnerabilities don't originate in the user interface but in the backend APIs that power it. We test following the OWASP API Security Top 10.
Authentication & Authorization
JWT token manipulation, OAuth flows, flawed scope validation, API key leakage in responses, BOLA (Broken Object Level Authorization), and BFLA (Broken Function Level Authorization).
Rate Limiting & Input Validation
Missing rate limiting (brute force on login endpoints), mass assignment, injection at query level, flawed input validation in JSON payloads, and parameter pollution.
Business Logic & GraphQL
Testing multi-step processes (order flows, payment processes), race conditions, GraphQL introspection, batching attacks, query depth, and field suggestion vulnerabilities.
OWASP API Security Top 10 - Our Test Catalog
- API1 Broken Object Level Authorization Critical
- API2 Broken Authentication Critical
- API3 Broken Object Property Level Authorization High
- API4 Unrestricted Resource Consumption High
- API5 Broken Function Level Authorization High
- API6 Unrestricted Access to Sensitive Business Flows Medium
- API7 Server-Side Request Forgery High
- API8 Security Misconfiguration High
- API9 Improper Inventory Management Medium
- API10 Unsafe Consumption of APIs Medium
Findings
What we typically find in web apps
Published CVEs from our vulnerability research:
Pricing
What does a web app pentest cost?
No hidden costs. No hourly rates. Fixed-price quote in 24 hours.
Single-Page App
from EUR 5,000
5-7 business days
- OWASP Top 10
- Up to 3 user roles
Popular
Complex Web App
from EUR 8,000
8-12 business days
- OWASP Top 10 + API Sec.
- Multiple roles + workflows
- Business logic testing
Enterprise + API
from EUR 12,000
10-15 business days
- Multiple microservices
- REST + GraphQL APIs
- SARIF output for CI/CD
Includes management summary and CVSS ratings. All prices ex. VAT.
Web App Pentest Retainer - plannable, regular, cost-effective
Quarterly tests at reduced rates - ideal for organizations that want to test after every major release, or for NIS-2 and PCI DSS compliance.
Compliance
Your web app pentest meets regulatory requirements
Our report is designed as compliance evidence covering the requirements of the most important regulations.
NIS-2 Directive
The NIS-2 Directive requires technical security measures including penetration testing for essential and important entities. Our report is designed as regulatory compliance evidence.
GDPR Article 32
GDPR Article 32 requires appropriate technical and organizational measures. Regular web app pentests are recognized as state-of-the-art and strengthen your legal position in data protection audits.
PCI DSS Req. 11.4
PCI DSS v4.0 Requirement 11.4 mandates regular penetration tests for merchants and service providers handling card data. Our report meets PCI DSS reporting requirements.
DORA Art. 26/27
The DORA regulation has required threat-led penetration testing (TLPT) for financial entities since January 17, 2025. Our approach follows TIBER-EU guidelines.
Why AWARE7 for Your Web App Pentest
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %From first contact to final report, your data is stored on our own servers in Germany - no US cloud providers, no third-country transfers. Our AI also runs on our own hardware in Germany - with locally operated open-source models. Client and project data never reach external AI services. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
More on digital sovereigntyFixed price within 24h: predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
References
Organizations that trust us
These case studies are available in German.
Getting Started
Three Steps to Your Web App Pentest
No lengthy procurement process. You talk to us - and we get started.
Initial Consultation
30 minutes, free of charge. We clarify scope, methodology, roles, and timeline for your web application.
Fixed-Price Quote in 24h
Binding, transparent, no hidden costs. You decide at your own pace - no pressure.
Pentest Begins
Our OSWA-certified team gets started. You receive ongoing updates and the report with a debrief session.
FAQ
Frequently Asked Questions about Web App Pentesting
What exactly is tested in a web application penetration test?
How does a web app pentest differ from an automated vulnerability scan?
How long does a web application penetration test take?
Are REST APIs and GraphQL also tested?
Can the pentest be integrated into our CI/CD pipeline?
What is the difference between black-box, grey-box, and white-box testing?
What does the pentest report contain?
How do I prepare my web application for the pentest?
How does the web app pentest help with NIS-2, GDPR, and other compliance requirements?
Aus dem Blog
Weiterführende Artikel
API-Sicherheit: OWASP API Top 10 und praktische Härtungsmaßnahmen
API-Sicherheit: OWASP API Security Top 10, BOLA und Mass Assignment - mit Codebeispielen für sichere Implementierung und API-Gateway-Härtung.
OWASP Top 10 2025: Kritische Web-Schwachstellen und Gegenmaßnahmen
OWASP Top 10 erklärt: alle 10 Kategorien mit Code-Beispielen, realen Angriffsszenarien und Gegenmaßnahmen für Entwickler und Sicherheitsverantwortliche.
Have your web application professionally tested for vulnerabilities
94% of web applications have security vulnerabilities (OWASP Top 10, 2021). Identify exploitable gaps across authentication, business logic, and APIs - with OSWA-certified experts and a fixed-price commitment.
Free · 30 minutes · No obligation