I’m looking for someone with web security experience to do a basic vulnerability and API exposure check on my website: https://www.mymaternalhub.co.uk
This isn’t a high-risk or enterprise-level system, but it will collect personal information, so I want to make sure there are no exposed API endpoints, admin panels, or misconfigurations that could put user data at risk.
I’d like you to:
Identify any exposed API endpoints
Check for open directories or admin pages
See if any sensitive files like .env, .git, server-status, etc. are publicly accessible
Look for common vulnerabilities (like XSS, CSRF, SQL injection)
Scan for subdomains or staging environments I may have forgotten about
Check if any secrets, tokens, or API keys are visible in frontend code
Review basic security headers and misconfigurations
Provide a simple report with what you found and what I should fix
Optional but appreciated: if you can recommend or help apply basic fixes like security headers or hardening steps.
This should be a non-invasive audit — I don’t want anything aggressive like brute-force attempts or DDoS tests. Just surface-level scanning and light probing using tools like OWASP ZAP, WPScan, Nikto, Nmap, or anything else you're comfortable with.
Road & Villa Pad Layout Designer – Hilly Terrain Category: 3D Design, 3D Drafting, 3D Modelling, 3D Rendering, AutoCAD, Civil Engineering, Environmental Engineering, Geographical Information System (GIS), Landscape Design Budget: $500 - $800 USD
15 Aug 2025 15:54 GMT
Manage Instagram Testimonial Photos Category: Content Creation, Facebook Marketing, Graphic Design, Instagram, Instagram Marketing, Social Media Management, Social Media Marketing, Social Networking Budget: $8 - $15 USD
15 Aug 2025 15:53 GMT
Fun Birthday Video Edit Category: Adobe Premiere Pro, After Effects, Animation, Creative Design, Video Editing, Video Post Editing, Video Production, Video Services Budget: £20 - £250 GBP