forumNew topic

Can we do mobile app security testing ourselves for free without paying an agency?

AAycan K***Member
Job title
Store Manager
Sector
Catering
Organization type
20-person company
Joined
Mar 2024
Message
132
#1

We built a mobile app for local barbershops and beauty salons in the US market to handle their appointment booking. We launched it on both iOS and Android stores two months ago, and we currently have around 1,300 active users. The system stores customer phone numbers, names, and past appointment history. We asked a security firm for a quote on a comprehensive mobile pentest, and they quoted us 3,800 USD.

Given our startup's current financial situation, that amount really stretches our budget. Before paying an external testing team that kind of money, how far can we get testing our mobile app's security on our own using free tools? Are automated online scans and open-source tools enough to catch basic vulnerabilities, and when should we actually get a professional test done?

VVeli T***Member
Job title
Human Resources Specialist
Sector
Agriculture
Organization type
120-person company
Joined
Apr 2023
Message
1
Most Helpful#2

Short answer: Yes, with open-source static and dynamic analysis tools, you can catch basic coding bugs, hardcoded sensitive keys, and unencrypted data transfers without spending a dime; however, these free checks won't fully audit your backend authorization logic or database vulnerabilities. So while free tools make for a great initial filter, they aren't a complete replacement for a professional test.

The process you can run on your own for free consists of three steps: 1) Set up an open-source security analysis platform on your machine and upload your app package; this scan will flag hardcoded API keys, insecure local file permissions, and excessive device permissions in minutes. 2) Set up a proxy tool to intercept traffic from your phone, and check whether the app sends sensitive data to the server in plaintext. 3) Run open-source dependency checkers that scan third-party libraries in your code for known CVEs.

These steps will catch the most common developer oversights. But once you integrate payment gateways, start signing enterprise deals, or cross tens of thousands of users, a professional pentest becomes inevitable. For now, it makes more sense to patch the obvious holes with free tools and save that 3,800 USD budget for growth.

SSinemExpert
Job title
Project manager
Joined
Oct 2023
Message
176
#3

First thing you should do is search your source code to see if any passwords, secret keys, or database connection strings were accidentally left behind. Free code scanners can spot those in seconds.

BBurak O***Member
Job title
Store Manager
Sector
Catering
Organization type
40-person manufacturing company
Joined
Oct 2023
Message
18

Doki · E-commerce infrastructure · 2026

#4

Most real vulnerabilities in mobile apps aren't on the client side, they're in the backend services. Try changing the user ID and fetching another salon's appointments; no automated free tool is going to catch those logic flaws on its own.

KKorhanExpert
Job title
B2B Sales Manager
Joined
Sep 2023
Message
162
#5

We ran tests with an open-source static tool on our first release and found a test token accidentally left in one of our libraries. It saved us from a critical leak before going live, without spending a dime.

YYasemin K***MemberCommunity member
Joined
Jan 2024
Message
82
#6

Don't upload your app package directly to those so-called 'free online security scan' websites. Handing your proprietary code over to third-party sites introduces a whole new security risk.

KKemal T***Member
Job title
IT manager
Sector
Accounting & advisory
Organization type
two-branch business
Joined
Nov 2023
Message
121

Doki · Corporate website · 2024

#7

Do these free tools also check for OS-level vulnerabilities on the phone or do they only look at the code we wrote?

Correction: I misremembered the figure, it was a bit lower.

VVahide V***Member
Job title
General Manager
Sector
Cosmetics
Organization type
workshop
Joined
Jul 2022
Message
1
#8

They only look at your app package and how it communicates with your server. OS patches on the phone are the manufacturer's responsibility; mobile testing is just about evaluating the security of your app.

PPerihan Ş***MemberCommunity member
Joined
Apr 2024
Message
1
#9

Someone I know had an app where booking IDs were sequential and a user just incremented the number in the URL and dumped the entire salon's customer list. It takes a watchful human to spot business logic flaws like that, not automated tools.

EEsra K***MemberCommunity member
Joined
Feb 2023
Message
3
#10

check your github history too sometimes even if u delete stuff from the code api keys are sitting right there in old commits.

LLevent Ş***ExpertCommunity member
Joined
Apr 2025
Message
14
#11

We need to take it step by step. If it's your first time, start small; scaling comes later.

If 2FA is on, a stolen password alone is useless. Just leaving this note it might be useful.

İİlker G***Member
Job title
Board member
Sector
Livestock
Organization type
regional distributor
Joined
Apr 2026
Message
341
#12

Do you think this works at any scale? Taking measures without an inventory leaves doors you haven't seen open.

Of course, it varies if your situation is different.

VVeli Ö***Expert
Job title
Accounting clerk
Sector
Logistics
Organization type
boutique agency
Joined
Jun 2025
Message
32
#13

I went through the same thing. People defend habits, not processes. Resistance comes from there.

Correct me if Im wrong.

OOrhan G***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
173
#14

the opposite happened to me, that's why I'm writing.. and hasty decisions become decisions you have to fix six moonths later.

MMerve K***Member
Job title
Supply chain manager
Sector
Retail
Organization type
a company within a holding
Joined
Apr 2025
Message
328

Doki · Infrastructure migration · 2026

#15

I think its hard to be that definitive about mobile app security testing. The answer varies greatly by industry; there is no one-size-fits-all rule.

Thats all sorry if I went on too long.

LLeyla Y***Member
Job title
Software developer
Sector
Plastic
Organization type
family business
Joined
Jun 2025
Message
96
#16

greaat work.

EEmine A***MemberCommunity member
Joined
Mar 2025
Message
1
#17

Let me summarize the topic since several different answers were given. Most time waste accumulates in tasks waiting for approval.

Start with a small trial; don't commit to everything at once.

DDilara T***Member
Job title
Social media manager
Sector
Logistics
Organization type
a company within a holding
Joined
Aug 2024
Message
333
#18

If I understood correctly, you're saying: If 2FA is on, a stolen password alone is useless.

I'm also curious if anyone does it differently.

AAli T***Member
Job title
Board member
Sector
Chemistry
Organization type
8-person team
Joined
Jun 2025
Message
334
#19

this thread is archived.

GGamze K***Member
Job title
Accounting Manager
Sector
Textile
Organization type
300-person organization
Joined
Jul 2024
Message
350

Doki · E-commerce infrastructure · 2026

#20

Thanks for posting.

Reply