TECHNOLOGIES: FORM.IO

Form.io Application Security Review

Form.io disables submission access by default, until a role is granted create access. We test which roles hold that access, and whether webhooks or JWT tokens extend it further. CREST-certified testers, fixed price from £2,270 for a 2-day single-application scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Form.io Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Roles

Every Form.io project ships four default Roles, and Submission Access is switched off for every form until a role is deliberately granted create_own or create_all.

Why Form.io findings sit in your role configuration, not the form builder

Form.io’s Roles and Permissions model grants every new project four default Roles, including Anonymous and Everyone, and Submission Access is disabled on every form until a role is explicitly given create_own or create_all. We test which roles actually hold that access on each form, and check for the documented interaction where a role granted update_all also receives create_all on the same Submission collection, whether or not that was intended. Form definitions themselves are readable by every role by default, so we check what a form’s own JSON schema discloses about validation logic and hidden fields before a submission is ever made.

Actions run server-side on submission, and a Webhook Action forwards a configurable payload to an external Request URL with an optional Basic Auth header or additional custom headers, transformable with custom JavaScript before it leaves Form.io. We test where each webhook actually points, whether the receiving endpoint enforces the authentication the action was configured with, and whether the transform script leaks more of the submission than the destination needs. Role Assignment Actions that add or remove a Role automatically on submission, commonly used for approval-style registration flows, get the same scrutiny, since the trigger condition is what decides who ends up privileged.

Authentication is delegated: OAuth, SAML or LDAP logins are mapped onto Form.io Roles after the external provider authenticates the user, and each Form.io session runs on a JWT carrying a session ID in its jti claim, invalidated project-wide on logout. We test whether that role mapping can be forced to a higher role than the provider intended, and how the API’s temporary-token pattern for exporting submission data is scoped. Field Level Encryption at rest is part of Form.io’s separately licensed Security Module rather than a default, so we confirm whether it is active before judging how sensitive fields are stored.

SCOPE

What we pen test on a Form.io application

FI-01

Form and Submission Access Roles

Submission Access is disabled on every form until a role is granted create_own or create_all. We test every role’s actual grants against what the form is meant to allow.

FI-02

create_all, create_own and the update_all Interaction

A role granted update_all also receives create_all on the same Submission collection. We test for a role that ended up able to create records it was only meant to edit.

FI-03

Public Form Definition Exposure

Forms allow every role to read their own JSON definition by default. We test what that schema discloses about validation rules, hidden fields and conditional logic before any data is submitted.

FI-04

JWT Sessions and Logout Invalidation

Each authenticated session runs on a JWT carrying a session ID in its jti claim, stored client-side as formioToken. We test whether logout genuinely invalidates every outstanding token tied to that session.

FI-05

OAuth, SAML and LDAP Role Mapping

External login providers authenticate the user, then Form.io maps the result onto a project Role. We test whether that mapping step can be manipulated into a higher-privilege role than the provider intended.

FI-06

Webhook Action Destinations and Payloads

A Webhook Action posts a configurable payload to an external URL, with optional Basic Auth or custom headers and an optional JavaScript payload transform. We test where each webhook points and whether the receiving side actually enforces the configured authentication.

FI-07

Role Assignment Actions on Submission

Role Assignment Actions add or remove a Role automatically when a submission meets a trigger condition, commonly used in approval workflows. We test whether that trigger can be met without the approval step it was meant to represent.

FI-08

Temporary Token Submission Export

The API issues temporary tokens for exporting submission data outside the normal session flow. We test how long a temporary token remains valid and what it can still reach once issued.

FI-09

Field Level Encryption and the Security Module

Field Level Encryption at rest is part of Form.io’s separately licensed Security Module, not a default. We confirm whether it is active on your project and test how sensitive submission data is actually stored if it is not.

FI-10

Self-Hosted vs Form.io-Hosted Deployment

Form.io is offered both as a hosted service and as a self-hosted developer platform. We scope the underlying server and database configuration into the test where your deployment is self-hosted.

OUR PROCESS

Form.io Application Security Review: From Scope to Attestation

01

Scope and Access Setup

You provide the project URL and credentials for the roles you want tested, from Anonymous through to Administrator.

02

Role and Permission Mapping

We enumerate every Role and its Form and Submission Access grants before testing a single form.

03

Manual Testing

Testers work role boundaries, Actions, webhooks and API endpoints against the mapped permission model.

04

Reporting and Retest

Findings are mapped to the specific Role or Action responsible, with a free retest once fixes are in.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Form.io pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Form.io Application Security Review Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,270–£3,340
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,330–£8,130
4 to 6 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Form.io Application Security Review

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

Do you need Administrator access to test our Form.io project?

We typically ask for an Administrator-role JWT plus credentials for at least one lower-privilege role, so we can test cross-role access rather than only what an admin can already reach. Exact access requirements are confirmed during scoping.

Does testing touch live submission data?

We test against a project you nominate for the engagement. If it holds live customer submissions, we agree data-handling rules with you before testing starts, and we can test against a cloned project instead if you prefer.

Do you test self-hosted and Form.io-hosted projects the same way?

The Role, Action and API model is the same in both cases. A self-hosted deployment adds the underlying server and database configuration to scope, which we agree with you upfront.

Is the Form.io Security Module in scope?

Only if you have licensed it. We test the Role, Action and API surface either way, and confirm during scoping whether Field Level Encryption is active on sensitive fields.

Does Form.io have a policy on penetration testing customer projects?

Form.io’s published security process asks anyone who finds a vulnerability to disclose it privately to security@form.io before going public, but it does not set out a separate customer pen-testing authorisation process. We confirm current terms during scoping.

What’s out of scope?

Form.io’s own multi-tenant hosting infrastructure is out of scope. We test your project: its Roles, forms, Actions, webhooks and API access.

How long does a Form.io review take?

The standard scope is 2 days for a single Form.io application. Projects with several environments or a large number of custom Actions may need more time, confirmed at scoping.

Can you test our OAuth, SAML or LDAP login integration?

Yes. We test how the external provider’s authentication result gets mapped onto Form.io Roles, and whether that mapping can be forced to a role the provider never intended to grant.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Form.io application

Form.io disables submission access by default, until a role is granted create access. We test which roles hold that access, and whether webhooks or JWT tokens extend it further. CREST-certified testers, fixed price from £2,270 for a 2-day single-application scope, quoted within 24 hours.