By Need - IT Security Overhaul

IT Security Overhaul

Full OWASP Top 10 audit for CI4, Laravel, WordPress, and Shopify platforms. Not a report and a goodbye - we implement every fix, re-test every finding, and deliver a signed security sign-off.

48hr
Report delivery
0
Outstanding after sign-off
48hr
Report delivery SLA
NDA
Before access granted
What We Look For

The vulnerabilities we find on every platform we audit.

These are not theoretical risks. These are real vulnerabilities we found and fixed on real platforms in the last 12 months. At least 4 of these 8 are present on every platform we have audited that was built by multiple developers over time.

A1
Broken Access Control (IDOR)
critical

Users accessing other users' data by changing an ID in the URL. The number one OWASP vulnerability category in 2024. Found in 5 of the last 6 CI4 platforms we audited.

A3
SQL Injection
critical

User input passed directly into database queries without sanitisation. Allows attackers to dump your entire database - customer records, payment data, admin credentials.

A2
Broken Authentication & Session
high

Weak session tokens, missing brute-force protection, no account lockout after failed logins, sessions that do not expire. Allows account takeover at scale.

A5
Missing CSRF Protection
high

Forms that process sensitive actions - password change, payment initiation, admin operations - without CSRF tokens. Users tricked into executing actions without their knowledge.

A4
Unrestricted File Upload
critical

File upload endpoints that accept PHP, executable files, or oversized payloads. Leads to remote code execution - the most dangerous path to full server compromise.

A5
Security Misconfiguration
medium

Debug mode enabled in production, default admin credentials, exposed .env files, verbose error messages, directory listing enabled. Trivial to exploit, often found on shared hosting.

A2
Exposed Sensitive Data
high

API keys, database credentials, and private keys committed to version control or exposed in client-side JavaScript. Especially common on platforms built by multiple developers over time.

A6
Vulnerable Dependencies
medium

Outdated WordPress plugins, old CI4 versions, unpatched PHP, npm packages with known CVEs. Running a security audit at the dependency level often reveals 20+ issues in an hour.

Real Audit Results

What we found and fixed on FliqhtIQ.

Every finding patched, every patch re-tested, and a signed sign-off at the end of it. These are the ones that mattered most.

critical
IDOR on /student/profile/{id}
Any logged-in user can view any student record by changing the ID. No ownership check.
high
Missing CSRF on admin actions
Password reset and role change endpoints accept POST without CSRF token.
critical
PHP file upload accepted
Profile photo upload accepts .php extension. No MIME validation.
high
Session does not expire
Admin sessions persist indefinitely with no idle timeout.
critical
SQL injection in search
Search parameter passed unsanitised into raw query.
medium
Debug mode in production
.env has CI_ENVIRONMENT=development in production deployment.
high
Exposed API key in JS bundle
Third-party API key visible in compiled frontend JavaScript.
medium
Outdated dependencies
5 Composer packages with known CVEs including one rated 9.8.
Every finding fixed, re-tested, and signed off.
By the Numbers

What our audits deliver.

48hr
Report delivery

Audit report with all findings delivered within 48 hours of access being granted.

0
Fixes outstanding

We do not hand over a report. We fix everything and re-test before sign-off. Broken access control is the commonest thing we find, and it is fixed the same way as everything else.

What you get after every audit
Prioritised findings report (Critical / High / Medium / Low)
Proof-of-concept for all critical findings
All fixes implemented (not just reported)
Re-test confirmation after every fix
Signed security sign-off document (for investor / compliance use)
How We Audit

Six steps from code access to signed sign-off.

We read source code, not just run scanners. Automated tools catch known CVEs. Only manual code review catches IDOR, business logic flaws, and developer mistakes.

1
Reconnaissance & mapping

We map every route, endpoint, parameter, and file upload point in your application. No black-box guessing - we read your source code.

2
Automated scan + manual review

Automated tools catch the obvious. Manual review catches the logic flaws, IDOR vulnerabilities, and business-logic bypasses that scanners miss.

3
Exploitation & PoC

For critical findings we produce proof-of-concept exploits - not just a report saying something might be vulnerable, but evidence that it is.

4
Prioritised report delivery

Every finding categorised by severity (Critical / High / Medium / Low), explained in plain English, with a specific remediation recommendation.

5
Fix implementation

We do not just report and walk away. We fix every finding ourselves - code patches, configuration changes, dependency updates. All included in the fixed price.

6
Re-test & sign-off

After fixes are applied, we re-test every finding to confirm resolution. You receive a signed security sign-off document - useful for investor due diligence.

Audit Types

Security audits for every platform we build on.

CI4 & Laravel Security Audit

Full OWASP Top 10 audit of your CodeIgniter 4 or Laravel application - IDOR, SQLi, broken auth, CSRF, file uploads, session management, and dependency CVEs. Delivered as a prioritised report with every fix applied.

Fixed-price Learn more

WordPress Security Audit

Plugin vulnerabilities, theme code review, user enumeration, XML-RPC exposure, file permission audit, and admin hardening. Especially critical for WooCommerce stores handling payment data.

Fixed-price Learn more

Shopify Security Review

Shopify apps permission audit, API key exposure check, checkout flow review, metafield injection testing, and theme code review for XSS vulnerabilities. Applicable to all Shopify Plus stores.

Fixed-price Learn more

Auth & Session Hardening

Shield auth configuration audit for CI4 - session fixation, brute force protection, remember-me token security, RBAC enforcement, and admin lockout policies.

Fixed-price Learn more

Penetration Testing

Manual penetration testing of your web application - authenticated and unauthenticated attack surfaces, business logic flaws, API security, and privilege escalation paths. Delivered with PoC exploit evidence.

Fixed-price Learn more

Ongoing Security Retainer

Monthly security monitoring - dependency CVE tracking, log review for anomalous access patterns, quarterly mini-audits, and emergency response for security incidents.

Monthly retainer Learn more
Engagement Options

Three ways to engage. All include fixes, not just reports.

One-time Security Audit

Full OWASP audit + all fixes implemented + re-test + sign-off. Fixed price, agreed before we start. Duration: 1–2 weeks depending on codebase size.

Audit + Hardening Sprint

Audit first, then a focused 2-week hardening sprint - auth system review, dependency updates, server configuration hardening, and admin access controls.

Ongoing Security Retainer

Monthly: dependency CVE monitoring, quarterly mini-audits, log anomaly review, and emergency incident response. For platforms with continuous development.

FAQ

Security questions we answer every week.

NDA signed before any access is granted. Everything is confidential.

Book Security Audit
What platforms do you audit?
CodeIgniter 4, Laravel, WordPress (including WooCommerce), and Shopify. We read your source code - not just run an automated scanner. This means our audits find logic flaws and IDOR vulnerabilities that automated tools miss entirely.
Do you fix issues or just report them?
We fix everything. Every finding in the report is patched by us - code changes, configuration updates, dependency upgrades. You receive a re-test confirmation and sign-off document. We do not hand over a 40-page PDF and leave.
How long does an audit take?
1–2 weeks for a standard web application (under 50 routes). Larger platforms with complex role systems take 2–3 weeks. We agree the timeline before starting and deliver on it.
What does the deliverable look like?
A structured report: executive summary, full findings list with severity ratings, technical description of each vulnerability, proof-of-concept evidence for critical issues, and remediation notes. Plus the implemented fixes and a re-test confirmation.
Can you work under NDA?
Yes. We sign NDA before receiving any access or code. All findings, client names, and vulnerability details are confidential. We do not reference client security findings without explicit written permission.
Is this useful for investor due diligence?
Yes - and this is one of the most common reasons clients come to us. Investors increasingly ask for security sign-off on platforms before Series-A. We deliver a signed re-test document that confirms all critical and high findings have been resolved.

Your platform has vulnerabilities. Find them before someone else does.

NDA before access. Fixed price before we start. Every finding patched before sign-off.