Published price

Application security review. A defined security review of a web application or API.

A scoped review of an application's security: the OWASP Top 10, how authentication and authorisation actually behave, access control between accounts, and the configuration and dependencies around it.

MVR 5,000 – 15,000. Prices are starting estimates. Final pricing depends on confirmed scope and requirements.

Prices in MVR

What it costs.

The range is the engineering, for a scope agreed in writing before anything starts. What decides where inside it a job lands is written out below.

Development MVR 5,000 – 15,000

Maintenance Scope-dependent

Scope-dependent. A retest after you have fixed the findings is quoted with the review.

MVR 5,000

A small application, one or two roles, a focused review.

MVR 15,000

A larger application, several roles and tenants, an API surface, and more to work through.

What moves it up:

  • How large the application is and how many roles it has
  • Whether there is an API to review alongside the interface
  • How many environments and integrations are in scope
  • Whether a retest after fixes is included

Prices are starting estimates. Final pricing depends on confirmed scope and requirements. Security testing scope is agreed in writing before any work begins.

Scope

What is in it, and what is not.

Both halves are published, because a list of everything included says nothing about the things it quietly leaves out.

What's included

  • OWASP Top 10 review
  • Authentication testing
  • Authorisation and access-control testing
  • IDOR and broken object-level authorisation checks
  • Dependency and known-vulnerability checks
  • Security configuration review
  • A written report of findings, in order of what matters

What's not

  • A full red-team engagement
  • Social engineering
  • Physical security
  • Compliance certification

Who it's for

  • Products about to go live
  • Applications handling customer data
  • Teams that have never had a second pair of eyes

This is an application security review, not a full penetration test and not a red-team engagement. Manual penetration testing is scoped separately through SkullSploit. Final scope is confirmed in writing before any testing begins.

Next

Price your own version of this.

The estimate builder starts from this range and adds what you actually need, in your browser, without sending anything anywhere.

Build an estimate How appsec review projects run

Every other published price

Back to pricing in full

Contact

Thinking about appsec review?

You don't need to know which service you need. Describe what's going on.

contact@skullsolutions.com

Ways to get in touch