TA AzeezCode

Application security · Authorised testing · Secure PHP

Temitayo Azeez

Web Application Security Engineer | Application Security | Secure PHP/Laravel Developer

Web Application Security Engineer with nearly 3 years of professional AppSec experience and 7+ years building PHP web applications. I identify vulnerabilities, review insecure code, guide remediation and retest fixes across production applications.

Certification
CompTIA Security+
Development
7+ years PHP
AppSec
Nearly 3 years
Professional photograph of Temitayo Azeez

Professional summary

Attacker perspective, developer discipline

I test applications the way an attacker would, then fix them the way a maintainer has to.

Application security engineering

Manual application security assessment, vulnerability analysis and practical remediation guidance across production web applications.

Web penetration testing

Authorised, scoped testing across authentication, authorisation, input handling and business logic, with evidence-backed reporting.

Secure code review

Manual review of PHP codebases focused on authentication, authorisation, injection, insecure input handling and other security-sensitive implementation flaws.

PHP development

Building and hardening MVC applications end to end: routing, validation, payment integrations, webhooks and audit logging.

Featured case studies

Findings, fixes and retests

Each case study documents context, scope, root cause, impact, sanitised evidence, remediation and verification.

high severity Access control

IDOR: missing server-side authorisation in an invoice workflow

An authenticated user could modify an invoice identifier and attempt to access another customer's resource. The remediation enforced ownership at the database query layer and was verified with positive and negative authorisation tests.

IDOR Broken Access Control Authorisation PHP

5 min read

high severity SSRF

SSRF in a server-side document import feature

An authorised security lab examining how a user-controlled URL can cause a web server to make unintended requests to internal or restricted destinations, followed by layered remediation and retesting.

SSRF Web Security PHP Input Validation

9 min read

high severity XXE

XXE in a legacy XML import parser

A supplier feed parser resolved external entities, exposing server-side file contents. Remediated by disabling entity loading, switching to a safe parser configuration and validating against a schema.

XXE Secure parsing Legacy code Retested

2 min read

All security case studies

Skills

Tools and standards I work with

Security testing

  • Burp Suite
  • OWASP ZAP
  • Nessus
  • Rapid7
  • Metasploit
  • Manual web application testing

Standards & methodology

  • OWASP Top 10
  • OWASP ASVS
  • OWASP WSTG
  • Authentication testing
  • Authorisation / IDOR testing
  • Business-logic testing

Secure development

  • PHP
  • Laravel
  • MySQL
  • REST APIs
  • Secure code review
  • Payment & webhook security

Infrastructure & tooling

  • Linux
  • Apache
  • VPS administration
  • Git / GitHub
  • SIEM
  • Active Directory

Methodology

How an engagement runs

Structured, repeatable and evidence-driven — from written authorisation through to retesting.

  1. 01

    Scope confirmation

    Written authorisation, in-scope hosts and applications, testing window, rules of engagement, emergency contacts and data-handling agreement before a single request is sent.

  2. 02

    Reconnaissance

    Passive information gathering, technology fingerprinting and documentation review, staying strictly inside the agreed scope.

  3. 03

    Attack-surface mapping

    Enumerating routes, parameters, roles, file handlers, integrations and background jobs to build a testable inventory.

  4. 04

    Authentication testing

    Credential handling, brute-force resistance, session issuance, fixation, logout, password reset and multi-factor flows.

  5. 05

    Authorisation testing

    Horizontal and vertical access control, IDOR, forced browsing and server-side enforcement of every client-side restriction.

  6. 06

    Input validation testing

    Injection classes, XSS contexts, SSRF, XXE, deserialisation and file-upload handling with safe, non-destructive payloads.

Full twelve-phase methodology

Development

Secure PHP applications I have built

Secure Laravel application

azeezcode.com — application security portfolio

A production Laravel portfolio built with security as a design requirement, including a nonce-based Content Security Policy, hardened HTTP response headers, CSRF protection, rate limiting, anti-spam controls and a published vulnerability disclosure policy.

Laravel Application Security CSP Secure Headers

7 min read

Financial services application

EverTrust Finance — secure financial-services application

A production financial-services platform handling loan applications, sensitive customer documents and administrative workflows, protected through layered authentication, access control, secure file handling and production hardening.

Application Security PHP Financial Services Access Control

10 min read

All development projects

Certification & professional training

Security credentials and hands-on learning

Certification

CompTIA Security+

Certified · 2025

Professional training

  • PortSwigger Web Security Academy — Web Security Training
  • TryHackMe — Web Fundamentals & Offensive Pentesting Paths
  • OWASP ASVS Level 2 — Self-Assessment Practice

Looking for an AppSec engineer who can also ship the fix?

I am available for application security engineering, secure code review and authorised penetration testing work.