TECHNOLOGIES: CODEIGNITER

CodeIgniter Penetration Testing

CodeIgniter’s CSRF filter only runs on the routes you register it for, so anything else submits unprotected. We test that coverage, Query Builder escaping, sessions and encryption keys. CREST-certified testers, fixed price from £2,560 for a 2-day single-framework scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
CodeIgniter Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Opt-in

CodeIgniter documents switching CSRF protection on as an edit to app/Config/Filters.php, and the same file lets routes be exempted or limited to specific HTTP methods, so its coverage is exactly what you configured there.

Why CodeIgniter’s protection is exactly what Filters.php, Routing.php and Security.php say it is

CodeIgniter’s Security class defaults to Cookie based CSRF protection, a double submit pattern, and its own documentation warns this will not stop same-site attacks once Session is also in use, recommending Session based protection instead, a synchronizer token pattern set by changing $csrfProtection to ‘session’ in app/Config/Security.php. Tokens regenerate on every submission by default through the $regenerate setting, and a redirect after a Cookie based submission needs withCookie() to resend the regenerated cookie.

Filters are wired up in app/Config/Filters.php: an alias in $aliases can point to more than one filter class at once, a $globals array applies filters before or after every request, and since v4.5.0 the execution order runs required, then globals, then methods, then route-specific filters. The same authentication gap we test on Laravel applications applies here: Auto Routing (Improved), disabled by default, maps any public, HTTP-verb-prefixed controller method straight to a URL once $autoRoute and $autoRoutesImproved are both turned on, so a new method can become reachable before anyone adds it to a route or a filter.

The Query Builder escapes values by default, but its own documentation is explicit that it is not designed to prevent SQL injection no matter what data you pass, and that a $escape parameter set to false, or a raw RawSql string, hands that protection back to you entirely. The same self-managed pattern runs through the rest of the framework: the encryption key in app/Config/Encryption.php picks OpenSSL or Sodium as its driver, and the session library defaults to a FileHandler with a 7200 second expiration and a ci_session cookie name, unless app/Config/Session.php says otherwise.

SCOPE

What we pen test on a CodeIgniter application

CI-01

CSRF Protection: Mode, Registration and Exceptions

CodeIgniter’s Security class defaults to Cookie based CSRF protection, a double submit pattern that its own documentation says will not stop same-site attacks once Session is also in use, so switching $csrfProtection to ‘session’ in app/Config/Security.php moves to a Session based synchronizer token instead; protection only actually runs on routes carrying the csrf alias in app/Config/Filters.php’s $globals array, which also accepts an except key, literal paths or regular expressions, to exempt specific URIs, the documented example being an endpoint that accepts externally posted content. We test which mode is configured, whether $regenerate and every exempted or method-scoped URI still need to sit where they do, and whether every state-changing form and redirect carries a valid token.

CI-02

Filter Aliases and Execution Order

Every filter needs an alias defined in app/Config/Filters.php’s $aliases array, a single alias can combine more than one filter class at once, and since v4.5.0 before filters run in the order required, globals, methods, filters, then route, with after filters reversed. We test what the filter:check command actually reports for each route in scope against what the alias, global and route-level configuration intended, since a filter combined into the wrong alias runs at a different point than expected.

CI-03

Auto Routing (Improved): Every Verb-Prefixed Method Becomes a Route

Auto Routing (Improved) is disabled by default, and once $autoRoute and $autoRoutesImproved are both turned on, any public controller method named with an HTTP verb prefix, such as getIndex() or postCreate(), becomes automatically reachable at a URL matching its class and method name, except for controllers already listed in Defined Routes. We test every controller in scope for a verb-prefixed method that was never meant to be public, since auto-routing exposes it the moment the method exists, not the moment someone adds a route for it.

CI-04

Query Builder Escaping, RawSql and $escape

The Query Builder escapes values passed to methods like where() and select() by default, but CodeIgniter’s own documentation states it is not designed to prevent SQL injection no matter what data you pass, and that a $escape parameter set to false, or a RawSql instance used for a compound statement, hands that protection back to the developer entirely. We test every query built with $escape disabled or with a RawSql string for what user input actually reaches it unescaped.

CI-05

Session Driver, Cookie Name and Expiration

Sessions default to the FileHandler driver with a 7200 second expiration and a ci_session cookie name, though app/Config/Session.php can switch to DatabaseHandler, MemcachedHandler, RedisHandler or ArrayHandler instead, each with its own storage caveats. We test which driver and savePath are actually in production, whether the expiration and cookie name match what the application needs, and, where DatabaseHandler is used, whether the ci_sessions table itself is reachable from outside the application.

CI-06

Environment, Boot Files and config:check

CI_ENVIRONMENT in the .env file, changeable with the spark env command, selects which file under app/Config/Boot runs, and CodeIgniter ships development.php, production.php and testing.php out of the box to control error display and other environment-specific behaviour. We test what the config:check command actually reports for the live App configuration values, baseURL, forceGlobalSecureRequests and CSPEnabled included, rather than trusting what a config file appears to set.

CI-07

Encryption Key Storage and Driver Choice

The encryption key set in app/Config/Encryption.php, or via the encryption.key environment variable using a hex2bin: or base64: prefix, protects whatever the Encryption service encrypts, and its driver is either OpenSSL, using AES-256-CTR by default, or Sodium; CodeIgniter’s own documentation warns this service must never be used for password storage, which needs PHP’s password hashing instead. We test how the encryption key was generated, where it is stored and who can read it, and whether anything sensitive, including passwords, was encrypted with it rather than hashed.

CI-08

File Upload Validation Rules

Uploaded files are only validated by a specific set of rules, uploaded[], is_image[], mime_in[], max_size[] and max_dims[] among them, since CodeIgniter’s own documentation notes the ordinary required rule cannot be used on a file input and uploaded[] has to stand in for it; a moved file’s hasMoved() flag then blocks the same UploadedFile instance from being moved a second time. We test what validation rule set is actually applied to every upload field in scope, and what happens when a file fails mime_in[], max_size[] or max_dims[] rather than being rejected outright.

CI-09

RESTful Resource Controllers and API Authentication

A controller extended from CodeIgniter’s ResourceController class and routed with $routes->resource() maps HTTP verbs to methods like index(), show(), create() and update() automatically, but the base class adds no authentication of its own, leaving that to whatever filter alias is applied to the route. We test every resource route for what authentication and authorisation actually sit in front of it, not what the ResourceController’s naming convention implies.

CI-10

The Wider PHP and Laravel Estate Around CodeIgniter

CodeIgniter applications often share a server, a database or a codebase with other PHP or Laravel components. Where that estate is wider than one CodeIgniter application, our PHP and Laravel penetration testing covers the rest of it.

OUR PROCESS

CodeIgniter Penetration Testing: From Scope to Attestation

01

Scope and Access

We agree the URLs, environments and accounts for every role your filters and CSRF configuration distinguish between, plus whether Auto Routing (Improved) or RESTful resource controllers are in use.

02

Configuration and Filter Mapping

We map app/Config/Filters.php aliases and execution order, CSRF protection mode, session configuration and where the encryption key is stored.

03

Manual Testing

A CREST-certified tester manually tests CSRF coverage, Query Builder escaping, auto-routed and resource controller endpoints, and file upload validation.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST CodeIgniter pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent CodeIgniter Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,560–£3,840
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£6,050–£9,270
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From CodeIgniter Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our CodeIgniter application?

We need at least one authenticated account for every role your filters and CSRF configuration distinguish between, plus route and controller source if Auto Routing (Improved) or RESTful resource controllers are in use.

Will testing touch our live data?

We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes and outbound emails, and we do not run destructive tests against real customer records without that agreement in writing.

How long does a CodeIgniter penetration test take?

A single CodeIgniter application sits in our 2-day single-framework scope, with a report typically landing around 5 working days after kickoff. An application with a wide Auto Routing surface, several resource controllers or a large integration footprint moves into a larger scope.

Do you test Auto Routing (Improved) as well as defined routes?

Yes. Where Auto Routing (Improved) is enabled, we test every controller method it can reach automatically alongside the routes defined explicitly in app/Config/Routes.php.

What is out of scope for a single-framework CodeIgniter test?

Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope and covered by our cloud penetration testing service instead. A separate frontend application consuming a CodeIgniter API is also scoped and quoted separately.

Do you need our source code?

No. Testing is black-box against the running application by default. A grey-box option, where we review the relevant Filters, Security and Session configuration alongside testing, is available if you want faster or deeper coverage of specific findings.

Does CodeIgniter have a customer penetration-testing policy we need to follow?

CodeIgniter is framework code you deploy and control yourself rather than a shared multi-tenant service. We confirm CodeIgniter’s and your hosting provider’s current terms during scoping before testing begins.

Do you test the database behind our CodeIgniter application?

We test how your CodeIgniter application’s Query Builder and raw queries handle input, not the database server’s own hardening; that sits under our database security review instead.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your CodeIgniter application

CodeIgniter’s CSRF filter only runs on the routes you register it for, so anything else submits unprotected. We test that coverage, Query Builder escaping, sessions and encryption keys. CREST-certified testers, fixed price from £2,560 for a 2-day single-framework scope, quoted within 24 hours.