CodeIgniter Penetration Testing
CodeIgniter’s CSRF filter only runs on the routes you register it for, so anything else submits unprotected. We test that coverage, Query Builder escaping, sessions and encryption keys. CREST-certified testers, fixed price from £2,560 for a 2-day single-framework scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CodeIgniter documents switching CSRF protection on as an edit to app/Config/Filters.php, and the same file lets routes be exempted or limited to specific HTTP methods, so its coverage is exactly what you configured there.
Why CodeIgniter’s protection is exactly what Filters.php, Routing.php and Security.php say it is
CodeIgniter’s Security class defaults to Cookie based CSRF protection, a double submit pattern, and its own documentation warns this will not stop same-site attacks once Session is also in use, recommending Session based protection instead, a synchronizer token pattern set by changing $csrfProtection to ‘session’ in app/Config/Security.php. Tokens regenerate on every submission by default through the $regenerate setting, and a redirect after a Cookie based submission needs withCookie() to resend the regenerated cookie.
Filters are wired up in app/Config/Filters.php: an alias in $aliases can point to more than one filter class at once, a $globals array applies filters before or after every request, and since v4.5.0 the execution order runs required, then globals, then methods, then route-specific filters. The same authentication gap we test on Laravel applications applies here: Auto Routing (Improved), disabled by default, maps any public, HTTP-verb-prefixed controller method straight to a URL once $autoRoute and $autoRoutesImproved are both turned on, so a new method can become reachable before anyone adds it to a route or a filter.
The Query Builder escapes values by default, but its own documentation is explicit that it is not designed to prevent SQL injection no matter what data you pass, and that a $escape parameter set to false, or a raw RawSql string, hands that protection back to you entirely. The same self-managed pattern runs through the rest of the framework: the encryption key in app/Config/Encryption.php picks OpenSSL or Sodium as its driver, and the session library defaults to a FileHandler with a 7200 second expiration and a ci_session cookie name, unless app/Config/Session.php says otherwise.
SCOPE
What we pen test on a CodeIgniter application
CSRF Protection: Mode, Registration and Exceptions
CodeIgniter’s Security class defaults to Cookie based CSRF protection, a double submit pattern that its own documentation says will not stop same-site attacks once Session is also in use, so switching $csrfProtection to ‘session’ in app/Config/Security.php moves to a Session based synchronizer token instead; protection only actually runs on routes carrying the csrf alias in app/Config/Filters.php’s $globals array, which also accepts an except key, literal paths or regular expressions, to exempt specific URIs, the documented example being an endpoint that accepts externally posted content. We test which mode is configured, whether $regenerate and every exempted or method-scoped URI still need to sit where they do, and whether every state-changing form and redirect carries a valid token.
Filter Aliases and Execution Order
Every filter needs an alias defined in app/Config/Filters.php’s $aliases array, a single alias can combine more than one filter class at once, and since v4.5.0 before filters run in the order required, globals, methods, filters, then route, with after filters reversed. We test what the filter:check command actually reports for each route in scope against what the alias, global and route-level configuration intended, since a filter combined into the wrong alias runs at a different point than expected.
Auto Routing (Improved): Every Verb-Prefixed Method Becomes a Route
Auto Routing (Improved) is disabled by default, and once $autoRoute and $autoRoutesImproved are both turned on, any public controller method named with an HTTP verb prefix, such as getIndex() or postCreate(), becomes automatically reachable at a URL matching its class and method name, except for controllers already listed in Defined Routes. We test every controller in scope for a verb-prefixed method that was never meant to be public, since auto-routing exposes it the moment the method exists, not the moment someone adds a route for it.
Query Builder Escaping, RawSql and $escape
The Query Builder escapes values passed to methods like where() and select() by default, but CodeIgniter’s own documentation states it is not designed to prevent SQL injection no matter what data you pass, and that a $escape parameter set to false, or a RawSql instance used for a compound statement, hands that protection back to the developer entirely. We test every query built with $escape disabled or with a RawSql string for what user input actually reaches it unescaped.
Session Driver, Cookie Name and Expiration
Sessions default to the FileHandler driver with a 7200 second expiration and a ci_session cookie name, though app/Config/Session.php can switch to DatabaseHandler, MemcachedHandler, RedisHandler or ArrayHandler instead, each with its own storage caveats. We test which driver and savePath are actually in production, whether the expiration and cookie name match what the application needs, and, where DatabaseHandler is used, whether the ci_sessions table itself is reachable from outside the application.
Environment, Boot Files and config:check
CI_ENVIRONMENT in the .env file, changeable with the spark env command, selects which file under app/Config/Boot runs, and CodeIgniter ships development.php, production.php and testing.php out of the box to control error display and other environment-specific behaviour. We test what the config:check command actually reports for the live App configuration values, baseURL, forceGlobalSecureRequests and CSPEnabled included, rather than trusting what a config file appears to set.
Encryption Key Storage and Driver Choice
The encryption key set in app/Config/Encryption.php, or via the encryption.key environment variable using a hex2bin: or base64: prefix, protects whatever the Encryption service encrypts, and its driver is either OpenSSL, using AES-256-CTR by default, or Sodium; CodeIgniter’s own documentation warns this service must never be used for password storage, which needs PHP’s password hashing instead. We test how the encryption key was generated, where it is stored and who can read it, and whether anything sensitive, including passwords, was encrypted with it rather than hashed.
File Upload Validation Rules
Uploaded files are only validated by a specific set of rules, uploaded[], is_image[], mime_in[], max_size[] and max_dims[] among them, since CodeIgniter’s own documentation notes the ordinary required rule cannot be used on a file input and uploaded[] has to stand in for it; a moved file’s hasMoved() flag then blocks the same UploadedFile instance from being moved a second time. We test what validation rule set is actually applied to every upload field in scope, and what happens when a file fails mime_in[], max_size[] or max_dims[] rather than being rejected outright.
RESTful Resource Controllers and API Authentication
A controller extended from CodeIgniter’s ResourceController class and routed with $routes->resource() maps HTTP verbs to methods like index(), show(), create() and update() automatically, but the base class adds no authentication of its own, leaving that to whatever filter alias is applied to the route. We test every resource route for what authentication and authorisation actually sit in front of it, not what the ResourceController’s naming convention implies.
The Wider PHP and Laravel Estate Around CodeIgniter
CodeIgniter applications often share a server, a database or a codebase with other PHP or Laravel components. Where that estate is wider than one CodeIgniter application, our PHP and Laravel penetration testing covers the rest of it.
OUR PROCESS
CodeIgniter Penetration Testing: From Scope to Attestation
Scope and Access
We agree the URLs, environments and accounts for every role your filters and CSRF configuration distinguish between, plus whether Auto Routing (Improved) or RESTful resource controllers are in use.
Configuration and Filter Mapping
We map app/Config/Filters.php aliases and execution order, CSRF protection mode, session configuration and where the encryption key is stored.
Manual Testing
A CREST-certified tester manually tests CSRF coverage, Query Builder escaping, auto-routed and resource controller endpoints, and file upload validation.
Reporting and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST CodeIgniter pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent CodeIgniter Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
2 to 3 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote3 to 4 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote5 to 7 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test CodeIgniter For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From CodeIgniter Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our CodeIgniter application?
We need at least one authenticated account for every role your filters and CSRF configuration distinguish between, plus route and controller source if Auto Routing (Improved) or RESTful resource controllers are in use.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes and outbound emails, and we do not run destructive tests against real customer records without that agreement in writing.
How long does a CodeIgniter penetration test take?
A single CodeIgniter application sits in our 2-day single-framework scope, with a report typically landing around 5 working days after kickoff. An application with a wide Auto Routing surface, several resource controllers or a large integration footprint moves into a larger scope.
Do you test Auto Routing (Improved) as well as defined routes?
Yes. Where Auto Routing (Improved) is enabled, we test every controller method it can reach automatically alongside the routes defined explicitly in app/Config/Routes.php.
What is out of scope for a single-framework CodeIgniter test?
Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope and covered by our cloud penetration testing service instead. A separate frontend application consuming a CodeIgniter API is also scoped and quoted separately.
Do you need our source code?
No. Testing is black-box against the running application by default. A grey-box option, where we review the relevant Filters, Security and Session configuration alongside testing, is available if you want faster or deeper coverage of specific findings.
Does CodeIgniter have a customer penetration-testing policy we need to follow?
CodeIgniter is framework code you deploy and control yourself rather than a shared multi-tenant service. We confirm CodeIgniter’s and your hosting provider’s current terms during scoping before testing begins.
Do you test the database behind our CodeIgniter application?
We test how your CodeIgniter application’s Query Builder and raw queries handle input, not the database server’s own hardening; that sits under our database security review instead.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your CodeIgniter application
CodeIgniter’s CSRF filter only runs on the routes you register it for, so anything else submits unprotected. We test that coverage, Query Builder escaping, sessions and encryption keys. CREST-certified testers, fixed price from £2,560 for a 2-day single-framework scope, quoted within 24 hours.



