Skip to content

Services / The review desk

Source code security review.

Understand the risks in your code—and what to do next.

AI-assisted review, personally triaged by me. Get reviewed findings, suggested fixes, and a plain-English report you can act on.

Dimas MaulanaSecurity researcher & CTF player

Explore my security write-ups

01 / Deliverables

Clarity, fixes, and a next step.

A reviewed result—not a raw scanner export.

Reviewed findings

AI-assisted codebase coverage with personal triage. Genuine issues, potential risks, and hardening notes are clearly distinguished.

Human-reviewed

Suggested fixes

A suggested patch for each finding, alongside dynamic checks that the program runs and behaves correctly.

Actionable changes

A report you can use

Plain-English PDF and Markdown reports, plus one free re-test after you apply the fixes.

PDF + Markdown + re-test

See the report before we talk.

Browse the published sample’s structure, findings, and suggested fixes to see whether the format fits your project.

Inside the sample report PDF / MD

  1. Executive summary
  2. Scope & methodology
  3. Findings & suggested fixes
  4. Hardening & next steps

02 / Scope

Know exactly what’s covered.

This is a source code review with program checks. It is not a live production or infrastructure pentest.

Private by arrangement

Isolated review workspace. NDA and code deletion after delivery are available on request. Agree on access before sharing your repository.

  • Static code review plus dynamic checks that the program runs correctly
  • No live production or infrastructure penetration testing
  • Languages: JavaScript and TypeScript, Python, PHP, Go, and most web backends
  • Turnaround is usually 1 to 2 days when I'm not busy
  • Patches are provided as-is, so test before you deploy

03 / Process

A straightforward handoff.

  1. Agree on scope

    Tell me about your project. We agree on scope and price, then arrange a private repo invite or ZIP.

  2. Review and check

    An AI agent reviews the code. I triage the findings and run the program to check its behavior.

  3. Report and follow up

    Receive the report and suggested fixes. Apply and test them, then use your included re-test.

04 / Questions

Before we start.

Not sure whether your project fits? Send a short overview and we can discuss the scope.

Ask about your project
Is this just an automated scanner?

It is AI-driven, but I triage every finding by hand and tell you which are actually exploitable, which are only potential, and which are just hardening. You get a reviewed report, not a raw tool dump.

What if you don't find anything?

You still get a report of everything the review checked, plus hardening notes. I won't pad it with findings that are not real.

Which languages do you cover?

JavaScript and TypeScript, Python, PHP, Go, and most web backends. Ask if yours is not listed.

How do I send my code?

A private GitHub or GitLab invite works best, but a plain zip over email is fine too. Whatever is easiest for you.

How does payment work?

We agree on the scope and price first, then you pay by bank transfer or your preferred method before I start.

Let’s work together

Start with a conversation.

Send your stack, approximate codebase size, concerns, and preferred timeline. We’ll agree on scope and price before you share access.

Choose whichever channel works for you.

No form to submit. Send only a project overview to start—not credentials or secrets.