1. Home
  2. Insights
  3. Web
Web

What a web application penetration test actually covers

Almost every web application test begins with a scoping document listing the same categories. The words are consistent, but what sits behind them varies enormously between one tester and the next. Here is what each area actually involves — and where the findings that matter usually come from.

Authentication and session handling

Authorisation — where most serious findings live

Business logic

Injection, SSRF and the rest

Client-side issues

APIs, which are usually the real scope

What a good report looks like

Start with the gaps, not the shopping list.

Book a 30-minute review. We will look at what you have and tell you the three things worth doing first.

Book a security review