I’m looking for someone with web security experience to do a basic vulnerability and API exposure check on my website: https://www.mymaternalhub.co.uk
This isn’t a high-risk or enterprise-level system, but it will collect personal information, so I want to make sure there are no exposed API endpoints, admin panels, or misconfigurations that could put user data at risk.
I’d like you to:
Identify any exposed API endpoints
Check for open directories or admin pages
See if any sensitive files like .env, .git, server-status, etc. are publicly accessible
Look for common vulnerabilities (like XSS, CSRF, SQL injection)
Scan for subdomains or staging environments I may have forgotten about
Check if any secrets, tokens, or API keys are visible in frontend code
Review basic security headers and misconfigurations
Provide a simple report with what you found and what I should fix
Optional but appreciated: if you can recommend or help apply basic fixes like security headers or hardening steps.
This should be a non-invasive audit — I don’t want anything aggressive like brute-force attempts or DDoS tests. Just surface-level scanning and light probing using tools like OWASP ZAP, WPScan, Nikto, Nmap, or anything else you're comfortable with.
Amazon Home Goods Listing Optimization Category: Amazon, Content Writing, Data Analysis, Internet Marketing, Keyword Research, Link Building, Search Engine Marketing (SEM), SEO Budget: ₹600 - ₹1500 INR
23-Oct-2025 16:04 GMT
Open-Plan Office Design Concept Category: 2D Drafting, 3D Modelling, 3D Rendering, 3D Visualization, AutoCAD, Building Design, Building Information Modeling, Interior Design Budget: $10 - $30 USD
Crypto Investor Lead Generation Category: Content Marketing, Cryptocurrency, Digital Marketing, Internet Marketing, Lead Generation, Leads, Social Media Marketing, Twitter Budget: ₹1500 - ₹12500 INR