Home / Penetration Testing / Web Application

Web Application
Penetration Testing

Manual, in-depth security testing of your web applications against the OWASP Top 10 and beyond — every finding verified by hand and scored with CVSS.

Overview

Test the app attackers target most.

Your web application is the front door to your business — and the first place an attacker looks. A web application penetration test is a controlled, authorised simulation of those attacks, designed to find exploitable vulnerabilities before someone malicious does.

We follow the OWASP Web Security Testing Guide and go well beyond automated scanning. Every finding is manually verified, scored with CVSS v3.1, and delivered with clear reproduction steps — not a wall of scanner false positives. We re-test your fixes free within 60 days.


Coverage

What we test.

Comprehensive coverage of the vulnerability classes that matter for modern web applications.

Methodologies: OWASP Top 10 OWASP WSTG v4.2 CWE Top 25 CVSS v3.1 PTES

FAQ

Web application penetration testing FAQ

The questions we're asked most about scope, cost, and timing.

How much does a web application penetration test cost?
A web application penetration test typically costs €2,000–3,500 for a small single application, €4,000–7,000 for a medium application with multiple roles, and €8,000+ for large enterprise platforms. Use our online estimator for a tailored figure.
How long does a web application penetration test take?
Most take between 3 and 10 working days of active testing, plus reporting. A small application is usually 3–5 days; a complex platform is 5–10 days or more.
What is the difference between black-box, grey-box, and white-box testing?
Black-box uses no prior knowledge, simulating an external attacker. Grey-box uses limited information and standard accounts, finding more issues for the same budget. White-box adds documentation and source-code access for the deepest coverage.
How often should we run a web application penetration test?
At least once a year, and after any major release or change to authentication, authorisation, or payment flows. ISO 27001, SOC 2, and PCI DSS all expect regular testing.
Do you provide a certificate or attestation letter?
Yes — a detailed technical report, an executive summary, and a summary attestation letter for customers and auditors, plus a free retest within 60 days.
What do you need from us to scope the test?
Usually the application URL(s), a short description of user roles and key features, and whether you want grey-box (test accounts) or black-box. We turn that into a fixed scope and quote within a day.
Do you test production or staging?
Either — we prefer a staging environment that mirrors production where possible, and agree rules of engagement for any testing against live systems.
Who carries out the testing?
Experienced, certified penetration testers — never an automated scan handed off as a report. Every finding is manually verified.
Is our data kept confidential?
Yes — we work under NDA, handle all findings securely, and can sign your data-protection terms before any engagement.
How quickly can you start?
Typically within 1–3 weeks of scoping, depending on availability and your preferred window.

Related services

Explore more.

Ready to test your web app?

A 30-minute scoping call costs nothing. A breach costs considerably more.

Book a meeting Send an email