
Closed
Posted
Paid on delivery
Title: Android APK Security Tester / VAPT Expert Required Hume apne Android application ka authorized security audit karwana hai. Hume ek experienced Android security tester chahiye jo APK, APIs aur backend communication ko test karke security vulnerabilities identify kare aur unke practical fixes bataye. Work Scope: - APK static aur dynamic security analysis - Authentication aur session security testing - API security testing - SQL Injection, IDOR, XSS aur access-control testing - SSL/TLS aur certificate pinning review - Sensitive data storage aur data leakage check - APK decompilation, code obfuscation aur tampering protection review - Root detection, emulator detection aur anti-debugging review - Hardcoded API keys, URLs, credentials aur secrets check - Firebase, WebView, permissions aur exported components review - Business-logic vulnerabilities aur unauthorized wallet/account access testing - OWASP Mobile Top 10 ke according complete assessment Required Deliverables: 1. Detailed VAPT report 2. Har vulnerability ka severity level: Critical, High, Medium ya Low 3. Vulnerability reproduce karne ke authorized steps 4. Screenshots ya supporting evidence 5. Risk explanation 6. Android, PHP/API aur server-side fixes 7. Fixes complete hone ke baad retesting report Testing sirf hamare provided APK, test accounts aur authorized server environment par ki jayegi. User data ko download, modify, delete ya publicly disclose nahi kiya jana chahiye. Tester ko confidentiality maintain karni hogi. Apply karte samay apna Android VAPT experience, relevant certifications, sample sanitized report aur estimated project cost share karein.
Project ID: 40586547
38 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
38 freelancers are bidding on average ₹25,666 INR for this job

Hello, I can help with your "Android APK VAPT Aur Security Audit Ki Avashyakta" project. I build clean, maintainable PHP backends — core PHP and Laravel/Symfony, MySQL schema design, and well-structured REST APIs. For work involving java, mobile app development, android, mysql, penetration testing, risk assessment, api testing, I pay close attention to validation, security, and readable code, delivering in small, testable milestones. You'll get clean commits and clear documentation. Could we discuss the specifics before I firm up the timeline? ⭐ 5.0/5 from a recent client: "They delivered the project well ahead of the committed delivery date. It was an experienced team, and I would be happy to hire them again." Final timeline and cost will be confirmed in chat after a complete understanding and documentation of the project expectations in detail.
₹30,000 INR in 7 days
7.9
7.9

Your app's security posture will determine whether you scale safely or face a data breach that destroys user trust. Most Android apps I audit have at least 3 critical vulnerabilities - hardcoded secrets, broken authentication, or insecure data storage - that attackers exploit within hours of launch. Quick questions - are you currently using certificate pinning to prevent MITM attacks? And what's your current obfuscation strategy for protecting API keys in the compiled APK? Here is the architectural approach: - PENETRATION TESTING: Execute OWASP Mobile Top 10 assessment covering static/dynamic analysis, decompilation via JADX, and runtime instrumentation using Frida to identify authentication bypasses and business logic flaws. - API TESTING: Test REST endpoints for SQL injection, IDOR, broken access control, and session hijacking using Burp Suite with custom scripts to validate token expiration and role-based permissions. - RISK ASSESSMENT: Deliver categorized report with CVSS scoring, proof-of-concept exploits, remediation code snippets for Java/Kotlin and PHP backend, plus retesting validation after fixes are deployed. I've conducted VAPT for 8 fintech and healthcare Android apps where I identified critical vulnerabilities before production launch. Let's schedule a 20-minute call to review your current security controls and testing timeline.
₹22,500 INR in 7 days
6.4
6.4

Hi, I reviewed your project: Android APK VAPT Aur Security Audit Ki Avashyakta. I can help you build, fix, or upgrade your Laravel/PHP application with secure authentication, database design, REST APIs, admin panels, payment integration, optimization, and deployment. I have strong experience with production Laravel systems, MySQL, JavaScript/React, API integrations, and server deployment. Please message me with the current codebase status and feature list so I can suggest the safest implementation plan. Portfolio: https://www.freelancer.com/u/irfanui Regards, Mohammad 4th Dimension Partners
₹37,500 INR in 44 days
6.1
6.1

Hello, I reviewed your complete requirements and understand that you need an authorized end-to-end Android application security assessment covering the APK, APIs, authentication, backend communication, data storage, and business logic in accordance with OWASP Mobile security standards. My approach will include structured static and dynamic APK analysis, API and access-control testing, authentication/session review, SSL/TLS configuration, sensitive-data exposure, hardcoded secrets, Firebase/WebView configuration, exported components, and business-logic security. All testing will remain strictly within your authorized environment and provided test accounts, with no unauthorized access or modification of user data. Deliverables will include a detailed VAPT report with Critical/High/Medium/Low severity classifications, reproducible evidence, risk explanations, practical Android/API/server-side remediation steps, and a follow-up retesting report after fixes are implemented. Quick questions: * Will you provide a staging/test backend along with the APK and test accounts? * Is the application built with native Android (Kotlin/Java), Flutter, or React Native? I can share relevant experience and sanitized examples of security assessment reporting during our discussion. After reviewing the APK and scope, I can also confirm the fixed cost and estimated timeline. Looking forward to hearing from you. Best Regards
₹25,000 INR in 3 days
5.8
5.8

Hello I am Cyber Security and Digital Forensics professional with 9 years of industry experience. I can conduct comprehensive penetration tests on the APK file following the industry accepted security benchmark of OWASP TOP 10 MOBILE and following manual testing, automated testing and reverse engineering for security loopholes and provide detailed VAPT report. I have experience of conducting more than 150 VAPT of Mobile, web and Network application. Regards Kajal Majhi
₹25,000 INR in 7 days
5.3
5.3

With a robust academic background in Computer Science and a Ph.D. in Artificial Intelligence under my belt, I bring two decades worth of professional experience to the table. My career has spanned the realms of academia, software engineering, and technology leadership, offering me a well-rounded skill set that covers all your needs and more. To further establish my competencies in line with the task at hand, I specifically focused on developing a deep understanding of SQL Injection, IDOR, XSS, access-control testing, cryptographic protocols like SSL/TLS an certificate pinning tightly integrated with API and Backend security testing. My tasks also encompassed Firebase and WebView usage paired with comprehensive assessment of permissions, exported components etc. As evident from my credentials and work experience pitch, I am supremely competent at detailed VAPT report writing supported by possible risks explained in access logs with evidence captured thoroughly on the scope of Stage 10 Owasap Mobile Test. Overall my practice straddles 円heroku, PHP/AI API + frontend calc site along with backend fix (of vulnerable app APIs) and retesting
₹12,500 INR in 7 days
4.6
4.6

Hello, I understand you need a professional Android VAPT assessment to identify security weaknesses across the APK, APIs, and backend communication, with actionable fixes rather than just automated scan results. I will perform a structured security review based on OWASP Mobile Top 10, including: • APK static and dynamic analysis • Authentication, session, and access-control testing • API security testing (IDOR, injection risks, authorization issues) • SSL/TLS and certificate pinning review • Sensitive data storage and leakage checks • Hardcoded secrets, API keys, and insecure configurations review • Firebase, WebView, permissions, and exported component analysis • Root detection, emulator detection, and anti-tampering review • Business logic security testing You will receive a detailed VAPT report containing vulnerability severity, technical impact, reproduction steps, evidence, risk explanation, and recommended fixes for Android/API/backend components. After fixes are applied, I can also assist with retesting and validation. All testing will be performed only on your authorized APK, test accounts, and environment while maintaining strict confidentiality. I would be happy to review your application details and provide a structured security testing plan. Best regards, Mohammed
₹28,000 INR in 7 days
4.3
4.3

We at Offensium Vault Private Limited (ISO 27001:2022 & ISO 9001:2015) can perform a comprehensive Android APK VAPT aligned with OWASP Mobile Top 10 and MASVS. Scope • Static & Dynamic APK analysis • Authentication, session & API security testing • SQLi, IDOR, XSS, access-control & business logic testing • SSL/TLS, certificate pinning, secure communication review • Sensitive data storage, data leakage & hardcoded secrets analysis • Root/emulator detection, anti-debugging & tamper protection review • Firebase, WebView, permissions & exported components assessment Tools MobSF, Burp Suite, Frida, JADX, Ghidra, APKTool, OWASP ZAP, Wireshark, and custom scripts Deliverables • Detailed VAPT report with Critical/High/Medium/Low severity ratings • Reproduction steps, PoC screenshots, and evidence • Risk explanation and Android, API/PHP, and server-side remediation guidance • Retest report after fixes We ensure strict confidentiality, test only within the authorized scope, and do not access or disclose user data. Redacted sample reports can be shared upon request, and we’re ready to start immediately.
₹30,000 INR in 7 days
3.6
3.6

As a seasoned Android VAPT expert, I bring extensive experience in APK security analysis, backend communication testing and identifying vulnerabilities specific to APIs to your project. With my 8 years of experience working with Apcomp Infotech LLP, Noida, I have developed a deep understanding of security protocols and best practices both at the code level and the backend. My robust skill set includes Mysql, Javascript, Ajax, Php, Nodejs, Angularjs and more - all necessary platforms to ensure the quality and robustness of your application. In addition to identifying potential threats such as SQL Injection, IDOR, XSS, Access-control issues and providing foolproof solutions accordingly, my deliverables would also include an OWASP Mobile Top 10 based thorough report that meticulously explains each vulnerability's severity and reproduces them while maintaining confidentiality. Furthermore, I am well-versed in conducting retesting procedures once the fixes have been made to guarantee complete security of your application. Meticulousness is my calling card as a professional; this means you can be assured that every step of your Android application's security will be thoroughly tested - from decompilation to tampering protection reviews and from sensitive data storage checks to unauthorized access probing. Hiring me for your project ensures you will have invested in someone genuinely dedicated to protecting your business from any cyber threats.
₹12,500 INR in 3 days
2.6
2.6

Hi, The best solution is to perform a complete **OWASP Mobile Top 10 VAPT** on your authorized APK, APIs, and backend to identify security vulnerabilities and provide practical remediation guidance. I'll deliver a detailed VAPT report with severity ratings, reproduction steps, screenshots, risk analysis, recommended Android/API/server-side fixes, and a retest report after the issues are resolved. I can also review obfuscation, certificate pinning, root detection, WebView, Firebase, exported components, and business logic vulnerabilities while maintaining strict confidentiality.
₹12,500 INR in 7 days
2.0
2.0

I'd love to help perform a complete security audit of your Android application. I have experience with Android VAPT, API security testing, and OWASP Mobile Top 10 assessments, focusing on identifying vulnerabilities and providing practical fixes. ✅ Complete APK, API, and backend security assessment ✅ Detailed VAPT report with severity levels and evidence ✅ Practical recommendations for Android, API, and server-side fixes ✅ Retesting after fixes with complete confidentiality I'd be happy to discuss your requirements and share relevant work samples during our conversation. Looking forward to working with you!
₹12,500 INR in 2 days
1.0
1.0

Hi, assessing the security of an Android APK requires a precise methodology for both static analysis and dynamic API communication testing. We approach this by conducting thorough decompilation and traffic interception to evaluate your existing authentication flows, session handling, and backend data integrity. Our workflow aligns with the OWASP Mobile Top 10, ensuring we catch vulnerabilities like hardcoded credentials, SSL pinning flaws, and broken access controls. Once the VAPT report is generated, we provide the corresponding patches for your PHP backend and server configuration. Could you clarify if the application currently implements certificate pinning and, if so, what library or framework is utilized for the implementation? The SimCodec Team
₹12,500 INR in 7 days
0.0
0.0

Hello, I have solid experience in Android application security testing and VAPT, including APK static/dynamic analysis, API security, and OWASP Mobile Top 10 assessments. I have performed audits covering authentication flaws, IDOR, SQL injection, insecure storage, SSL/TLS misconfigurations, and reverse engineering risks, along with providing clear, practical fixes for both Android and backend systems. I follow a structured approach using tools like MobSF, Burp Suite, Frida, and manual testing to identify vulnerabilities, document reproducible steps, and deliver detailed reports with severity levels, evidence, and remediation guidance. I can also provide a sanitized sample report and estimate the project cost after reviewing your APK scope, ensuring full confidentiality and compliance with your requirements. So I am sure I can complete this project perfectly as you want. Please send me a message so that we can discuss more. Thanks
₹30,000 INR in 7 days
0.0
0.0

नमस्ते, मैंने android apps का authorized vapt पहले किया है, और असली चुनौती business-logic issues जैसे unauthorized wallet access पकड़ना है जो automated scanners miss कर देते हैं। apk का static aur dynamic analysis करूंगा, फिर auth/session security, api testing, sql injection, idor, xss, ssl pinning, aur hardcoded secrets check करूंगा। root/emulator detection aur webview/firebase config owasp mobile top 10 ke hisab se cover hoga। har vulnerability severity, reproduce steps, screenshots ke saath report hogi, fixes ke baad retest bhi included। sanitized sample report request par bhej sakta hun। apna test apk aur access details bhejein, main aaj shuru karta hun।
₹18,000 INR in 7 days
0.0
0.0

As an experienced Android developer with a specialized focus on security, I am confident that I am the perfect fit for your Android APK Security Testing and VAPT project. With over five years of professional experience, I have actively strengthened my skills in understanding and resolving the security vulnerabilities apparent in mobile applications. I possess a comprehensive understanding of VAPT and have proven expertise in conducting detailed assessments following OWASP Mobile Top 10 guidelines while maintaining user data confidentiality. Aside from my front-end and back-end development proficiency with Java, my knowledge extends closely to databases like MySQL where I understand the importance of securely handling data within any system. Demonstrating a commitment to detail, all vulnerabilities identified will be ranked based on respective levels of severity, thoroughly explained, and provided with authorized steps to reproduce them for your convenience. By partnering with me, you gain access to not only a talented developer but also an effective communicator who appreciates the significance of feedback loops within collaborative projects. I am dedicated to not only identifying vulnerabilities but also ensuring reliable fixes are implemented - retesting for assurance right until the endpoint.
₹25,000 INR in 7 days
0.0
0.0

Namaste, I've worked on similar Android VAPT engagements and noticed one mistake many testers make - relying only on automated scanners, when real risks like business-logic flaws and wallet/account takeover paths surface only through manual exploitation. I combine static + dynamic analysis with hands-on manual testing to catch what tools alone miss. Scope I'll Cover APK static/dynamic analysis, decompilation, tamper/obfuscation review Auth & session security, SSL/TLS, certificate pinning API security: SQLi, IDOR, XSS, broken access control Sensitive data storage, leakage, hardcoded keys/secrets/URLs Firebase, WebView, exported components, permissions review Root/emulator detection, anti-debugging bypass Business-logic and unauthorized wallet/account access testing Full OWASP Mobile Top 10 assessment Deliverables Detailed VAPT report with severity ratings (Critical/High/Medium/Low) Authorized reproduction steps with screenshots/evidence Risk explanation per finding Practical Android, PHP/API, and server-side fixes Retesting report post-remediation Strict authorized-scope testing only - no data download, modification, or disclosure - full confidentiality maintained throughout. Happy to share my VAPT experience, certifications, and a sanitized sample report once we connect, along with a fixed cost based on your APK's scope
₹25,000 INR in 7 days
0.0
0.0

Hello, I can do an authorized Android VAPT assessment , spanning the APK, APIs, auth mechanisms, backend communication, local storage, permissions, WebView, Firebase, exported components, SSL/TLS, and the business-logic angle. I am also comfortable with OWASP Mobile Top 10 style checks, and both static plus dynamic APK analysis, including API authorization verifications, IDOR patterns, injection vectors, hardcoded secrets, tampering protections and secure session handling—like really. I will operate only inside the given APK, use the test accounts that you provide, and stay within the approved server environment. At the same time I’ll keep strict confidentiality , and I will avoid any effect on real user data or production behavior. You can expect a structured report with severity ratings, step by step test flows that are authorized and reproducible, evidence captures, clear risk explanations, and actionable remediation advice. This will cover Android changes, PHP/API adjustments, and server side components too. Once the fixes are applied, I can run a retest cycle on the same areas and deliver a clean verification result that shows which findings are gone and which ones are still open. If you want, I can also share a sanitized report template , and help define the final cost after I review the APK scope, the backend endpoints, and the level of testing access that’s granted. Best regards, Jose S.
₹25,000 INR in 5 days
0.0
0.0

As a seasoned Android APK VAPT (Vulnerability Assessment and Penetration Testing) specialist backed by a team of expert developers, Vision Solutions understands the significance of thorough security audits like the one you require. Our expertise in identifying and resolving vulnerabilities through rigorous testing puts us in a prime position to ensure your application is watertight. Our experience extends to APK static and dynamic security analysis, API and backend security testing, storage leakage checks, among other key areas mentioned in your project scope. We have ample knowledge in dealing with multiple types of security loopholes like SQL Injection, IDOR, XSS and access control testing, an essential skill for thorough VAPT assessments. Additionally, we have mastered OWASP Mobile Top 10 standards and will provide you with a comprehensive report along with well-defined vulnerabilities' severity levels and their authorized reproduction steps. Why choose Vision Solutions for this audit? We understand that technology builds the foundation but security strengthens and maintains it. Our client-centric, transparent approach ensures we work collaboratively and remain aligned with your data protection policies. Together, let's build an empowered digital world where reliable apps protect all users' information. I eagerly look forward to discussing your project in detail.
₹12,500 INR in 7 days
0.0
0.0

I can perform an in-depth Android VAPT for your APK, APIs, and backend aligned with OWASP Mobile Top 10, focusing on auth/session flaws, business logic issues, data leakage, and wallet/account abuse without touching real user data. I’ve led Android security audits for fintech and wallet apps, including static/dynamic analysis, API abuse, SSL pinning, root/emulator checks, obfuscation, and reverse engineering. I hold [Your Certification] and can share a sanitized sample report. My approach: structured recon, static/dynamic testing, exploit proof-of-concept, and clear remediation guidance for Android, PHP/API, and server, followed by retesting. Please share APK, scope, and budget so I can estimate cost and timeline. I would love to chat more about your project! Regards
₹12,500 INR in 2 days
0.0
0.0

Hey! Coming from a full-stack development background, I bring a unique perspective to the table when it comes to Android APK security testing. While I have extensive experience in mobile app development using Java and MySQL, my skill set reaches beyond just writing code. With a comprehensive understanding of APIs, backend architecture, and data storage protocols, I'm confident in my ability to identify and resolve potential security vulnerabilities within your Android application. Over the years, I've been trusted by various businesses globally to automate and scale their operations securely. Pairing this experience with my firm grasp on OWASP Mobile Top 10, I can guarantee a meticulous and practical approach to every aspect of your VAPT. From scrutinizing SSL/TLS certificates to decompilation and tampering protection review, I leave no stone unturned in securing your application. My goal with every project is to build solutions that not only meet immediate needs but also create long-term value. And this aligns perfectly with your project's vision - ensuring the confidentiality of user data during the entire testing process. So let's dive into this endeavor together, where you get more than just an expert in Android VAPT; you get a partner committed to helping your business grow securely and consistently.
₹15,000 INR in 20 days
0.0
0.0

Pune, India
Member since Nov 28, 2025
₹12500-37500 INR
₹12500-37500 INR
₹1500-12500 INR
$2-10 USD / hour
₹7500-15000 INR
$10-15 USD
₹3500-4000 INR / hour
$15-25 USD / hour
₹600-1500 INR
$15-25 USD / hour
₹12500-37500 INR
$250-750 AUD
₹12500-37500 INR
$3000-5000 USD
$250-750 USD
$50000-100000 USD
£20-250 GBP
₹400-750 INR / hour
₹100-400 INR / hour
$25-50 USD / hour
₹12500-37500 INR
$750-1500 USD
$250-750 USD