I’m looking for someone with web security experience to do a basic vulnerability and API exposure check on my website: https://www.mymaternalhub.co.uk
This isn’t a high-risk or enterprise-level system, but it will collect personal information, so I want to make sure there are no exposed API endpoints, admin panels, or misconfigurations that could put user data at risk.
I’d like you to:
Identify any exposed API endpoints
Check for open directories or admin pages
See if any sensitive files like .env, .git, server-status, etc. are publicly accessible
Look for common vulnerabilities (like XSS, CSRF, SQL injection)
Scan for subdomains or staging environments I may have forgotten about
Check if any secrets, tokens, or API keys are visible in frontend code
Review basic security headers and misconfigurations
Provide a simple report with what you found and what I should fix
Optional but appreciated: if you can recommend or help apply basic fixes like security headers or hardening steps.
This should be a non-invasive audit — I don’t want anything aggressive like brute-force attempts or DDoS tests. Just surface-level scanning and light probing using tools like OWASP ZAP, WPScan, Nikto, Nmap, or anything else you're comfortable with.
Cleopatra speaking to audience Category: After Effects, Audio Editing, Post Production, Video Conferencing, Video Editing, Video Production, Video Services, Video Streaming Budget: $30 - $250 USD
PHP/Laravel API Integration Support Category: API, API Development, API Integration, Laravel, MySQL, PHP, RESTful, Software Architecture Budget: $10 - $30 USD
18-Jan-2026 16:55 GMT
Detachable AR Mount Design Category: 3D CAD, 3D Design, 3D Printing, Manufacturing Design, Mechanical Engineering, Product Design, Solidworks Budget: $30 - $250 USD
Automate PDF Generation from Form Inputs Category: API Development, Automation, Data Integration, JavaScript, Node.js, PHP, Programming, Python, Software Development, Web Development Budget: ₹12500 - ₹37500 INR