Web Application Pentest Readiness Check
Fifteen yes/no questions that measure how ready your web application and APIs are for a penetration test, based on OWASP practice.
- 15 questions
- ± 6 minutes
Frequently asked questions
What standard is web application pentesting based on?
The OWASP Testing Guide and OWASP ASVS for methodology, with the OWASP Top 10 as the primary risk classification reference.
How long does a web application test take?
Usually 1 to 2 weeks for a small-to-medium application, depending on the number of pages, user roles and API endpoints covered.
What is the difference between black-box, grey-box and white-box testing?
Black-box has no access, simulating an outside attacker. Grey-box uses limited test accounts to find authorisation flaws. White-box has source code access for the deepest analysis.
Are mobile applications covered by this questionnaire?
No, this questionnaire focuses on web applications and APIs. For Android/iOS mobile app testing, see our Security Assessment services page.
Plan the web application test with our team
Web application and API pentests by an OSCP-certified team following the OWASP Testing Guide, with CVSS v3.1 reporting and a free retest.