forumNew topic

How can we do our own site security testing, and what should we check before a pentest?

YYavuzExpert
Job title
Information Security Manager
Joined
Jul 2023
Message
168
#1

We are an 8-person team based in Paris running a B2B e-commerce platform for wholesale orders. The site stores current account details, past invoices, and order details for our corporate clients. Last week, we received a quote of 4,500 EUR from an independent third-party expert for a comprehensive web penetration test. Honestly, with our current cash flow, that budget is a bit of a stretch for us right now.

Before accepting the quote, we want to at least scan for and patch obvious vulnerabilities, basic misconfigurations, and simple flaws on our own. The developer on our team knows general web development, but isn't a security specialist. We’d like to kick off the process with a pre-audit we can conduct ourselves.

What should our DIY site security testing cover, and which checks can we verify using free or basic methods? Also, at what point do these self-tests fall short and professional services become inevitable?

RRıdvan K***MemberCommunity member
Joined
Oct 2024
Message
77
Most Helpful#2

Short answer: Before bringing in a professional penetration test you can fully audit your SSL/TLS configuration, HTTP security headers default admin panel paths and out-of-date software components yourself. These baseline steps close the automated discovery holes attackers exploit most, though they won't catch business logic flaws.

Follow these steps when doing your own security testing: 1) Test your web server's certificate and encryption strength using free online SSL analysis tools, and disable weak protocols. 2) Check if your server returns headers that harden browser security; ensure Content Security Policy and frame-blocking settings are enabled. 3) Test whether sensitive paths like the admin dashboard phpinfo, or database management interfaces are exposed publicly by typing their URLs directly in an incognito tab. 4) Look up the version numbers of your CMS, libraries and server packages against known vulnerability databases.

Free automated scanners only catch known signatures and superficial errors. They won't spot business logic flaws such as whether a user can view another client's invoice just by changing a number in the URL (an IDOR vulnerability) or whether an order can be placed with a negative cart total.

If your site handles credit limits or confidential pricing agreements for your B2B customers your self-testing can only serve as groundwork. If you patch all the low-hanging fruit before hiring the expert who quoted 4,500 EUR, the pentester won't waste billable hours on trivial issues and can focus on deep authorization and business logic testing, giving you full value for your money.

OOsman T***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
a company within a holding
Joined
Jan 2022
Message
3
#3

Testing things yourself first is a very smart move. If you start a pentest while there are simple, known flaws on your server, the final report will just be pages of telling you to update your packages, which wastes your money. Lock your own front doors first, then let the expert test how solid the deadbolts are.

HHilal B***ExpertCommunity member
Joined
Feb 2026
Message
66
#4

We were in a similar spot last year. We couldn't afford a 4,000 EUR budget, so we spent 3 days updating all our software packages and fixing HTTP headers. The narrowed-down scope pentest we ordered after that only cost 1,800 EUR because the expert stepped into a clean, prepared system.

EElif B***Member
Job title
Store associate
Sector
Chemistry
Organization type
workshop
Joined
May 2023
Message
55

Doki · SEO consulting · 2024

#5

Do this tonight: create two different B2B test accounts on the site. Log in with one and place an order, then copy the order ID from the URL and try opening it in the second user's browser. If the other user's data loads, you've just caught your biggest vulnerability for free.

PPınarExpert
Job title
Analytics Specialist
Joined
Jan 2024
Message
198

Doki · Mobile app · 2025

#6

Don't rely too heavily on off-the-shelf open-source security scanners off the web. They usually generate thousands of false alarms, which will overwhelm your developer and might cause them to miss the genuinely critical authorization flaws.

OOsman K***MemberCommunity member
Joined
Mar 2024
Message
117
#7

Here is the bare minimum checklist you can do yourselves: 1) Prevent error messages from displaying server software and database versions. 2) Add rate limiting to your login screens to stop brute force attempts. 3) Make sure database backup files haven't been left behind in a public web directory.

KKemalNew member
Job title
Farm business
Joined
Sep 2024
Message
42
#8

Tell your dev not to sweat it, there are great free analysis sites out there that grade your security headers. You plug in the URL and it gives you a grade from A to F. tbh just putting in the work to get that grade up to an A will tighten the system up considerably.

RRamazan G***Expert
Job title
Secretary
Sector
Leather
Organization type
20-person company
Joined
Apr 2022
Message
92

Doki · Mobile app · 2025

#9

forgotten test accounts and weak passwords on the admin panel open the door to more than half of external attacks, check everyones passwords and 2fa before running automated scans imo.

NNuri K***Member
Job title
Product Manager
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
3
#10

Please make sure to run your internal testing outside of business hours and on a backup copy of your live environment. Heavy automated traffic can trigger database deadlocks or service downtime in production.

MMetin Ö***MemberCommunity member
Joined
Aug 2024
Message
356
#11

I have a question. When you try to change everything at once, nothing settles.

This is my opinion, I'm not claiming it's absolute truth.

FFurkan U***MemberCommunity member
Joined
Dec 2024
Message
266
#12

Noted, thanks. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Having backups accessible on the same network and with the same identity makes them part of the target.

AAylinMember
Job title
CRM and email
Organization type
300-person organization
Joined
Jun 2024
Message
118
#13

The most overlooked point about site security testing is this: The biggest time-waster for us was not knowing who had the final say.

Of course, it varies if your situation is different.

FFerhat A***Member
Job title
Board member
Sector
Advertising and promotion
Organization type
20-person company
Joined
Jun 2024
Message
155
#14

Let me summarize what's been said so far. If you scold false alarms, nobody will report again.

I'm also curious if anyone does it differently.

ZZehra D***Veteran
Job title
Courier coordinator
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Jun 2023
Message
80
#15

Noted, thanks.

VVeli Ö***Expert
Job title
Accounting clerk
Sector
Logistics
Organization type
boutique agency
Joined
Jun 2025
Message
32
#16

Let me summarize the topic, since several different answers were given. The real issue isnt the number, but what its based on.

If you post the result here, it will help others too.

ZZehra Y***MemberCommunity member
Joined
Oct 2023
Message
56
#17

this is exactly what we experienced and if you scold false alarms, nbody will report again.

this is my opinion I'm not claiming it's absolute truth.

ÖÖzge C***Expert
Job title
Purchasing manager
Sector
Cosmetics
Organization type
300-person organization
Joined
Mar 2023
Message
141
#18

I'll try it.

UUfuk G***New member
Job title
General coordinator
Sector
IT services
Organization type
regional distributor
Joined
Jun 2026
Message
188

Doki · Backup setup · 2026

#19

let me summarize the topic since several different answers were given then like any unwritten clause becomes a point of disagreement later as both siddes remember it differently.

i'm also curious if anyone does it differently.

KKübra D***MemberCommunity member
Joined
Mar 2022
Message
213
#20

Timely topic.

Reply