I’m looking for someone with web security experience to do a basic vulnerability and API exposure check on my website: https://www.mymaternalhub.co.uk
This isn’t a high-risk or enterprise-level system, but it will collect personal information, so I want to make sure there are no exposed API endpoints, admin panels, or misconfigurations that could put user data at risk.
I’d like you to:
Identify any exposed API endpoints
Check for open directories or admin pages
See if any sensitive files like .env, .git, server-status, etc. are publicly accessible
Look for common vulnerabilities (like XSS, CSRF, SQL injection)
Scan for subdomains or staging environments I may have forgotten about
Check if any secrets, tokens, or API keys are visible in frontend code
Review basic security headers and misconfigurations
Provide a simple report with what you found and what I should fix
Optional but appreciated: if you can recommend or help apply basic fixes like security headers or hardening steps.
This should be a non-invasive audit — I don’t want anything aggressive like brute-force attempts or DDoS tests. Just surface-level scanning and light probing using tools like OWASP ZAP, WPScan, Nikto, Nmap, or anything else you're comfortable with.
Playful Three Brand Website Build Category: CSS, Graphic Design, HTML, JavaScript, PHP, Web Design, Web Development Budget: $30 - $250 AUD
28-Nov-2025 05:03 GMT
Daily Email & Travel Organizer Category: Admin Support, Business Writing, Customer Service, Medical, Medical Billing And Coding, Medical Devices Sales, Medical Research, Medical Writing, Time Management, Virtual Assistant Budget: ₹12500 - ₹37500 INR
Purchase Data Update Assistant Category: Data Analysis, Data Cleansing, Data Entry, Data Processing, Excel, PDF, Visual Basic, Word Budget: ₹1500 - ₹12500 INR