Liferay Penetration Testing
One Liferay instance can run many Sites and Organisations, and a role granted at the wrong scope crosses between them. We test whether Site, Organisation and Guest permissions hold that boundary. CREST-certified testers, fixed price from £3,480 for a 3-day single-framework scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Liferay’s own default roles reference documents three permission scopes, Regular, Site and Organisation, and a role granted at the wrong one reaches further than the page it was meant to cover.
Why Liferay findings sit in scope and role configuration, not the platform
Liferay’s own default roles reference splits permissions into three scopes: Regular roles that apply across the whole instance, Site roles scoped to one Site, and Organisation roles scoped to one Organisation. The Guest role covers every visitor who has not signed in, and what it can reach on a public page or a public API is set independently of what a signed-in User can reach. We test what each scope actually grants against what your organisation intended it to grant.
A Site Administrator can manage almost every part of a Site but cannot remove another Site Administrator or Site Owner, and Liferay’s documentation notes that duplicating a Site Administrator’s ability to view Users outside the Site needs a separate Regular role, because a custom Site role cannot grant it. Where an Organisation has an attached Site, its Organisation Users and Administrators map straight onto Site Member and Site Administrator, so a change made at the Organisation level moves people between access levels on the Site without a separate decision. We test custom roles and Organisation-to-Site mappings for the gap between what an admin meant to grant and what the mapping actually grants.
Liferay’s headless REST APIs and JSON web services require authentication by default, and a Service Access Policy is the control that opens a specific method to unauthenticated requests instead. Liferay’s own documentation notes that a policy cannot discriminate within the GraphQL endpoint the way it can for individual REST resources, because every GraphQL call shares one endpoint, so widening GraphQL access risks exposing more than the one method a policy was written for. We test which service access policies exist on your instance, what each one exposes, and whether GraphQL access was opened wider than its REST equivalent.
SCOPE
What we pen test on a Liferay instance
Site, Instance and Organisation Boundaries
A single Liferay instance can host many Sites and Organisations, each meant to keep its users, content and permissions separate. We test whether that boundary holds, in the same way we check site and tenant boundaries on other multi-site platforms, or whether a shared user group, an inherited role or a misconfigured Organisation Site lets access cross from one Site into another.
Regular, Site and Organisation Role Permissions
Liferay assigns permissions through Regular roles that apply instance-wide, Site roles scoped to one Site, and Organisation roles scoped to one Organisation, and the same permission name can reach a different amount of data depending on which scope it was granted at. We test every custom role against its documented scope, including whether a Site Administrator or Organisation Administrator can reach further than Liferay’s own boundary for that role allows.
Guest Role and Public Page Exposure
The Guest role covers every visitor who has not signed in, and what it can view or do is set independently on every page, portlet and API method. We test public pages and the Guest role’s permissions together, looking for a widget, folder or API method left reachable to Guest that your team intended to restrict to signed-in Users.
Portlet and Widget Permission Configuration
Every widget carries its own permissions tab, covering View, Configuration, Preferences and Add to Page independently of the page’s own access controls, so a page restricted to one role can still host a widget left open to a wider one. We test widget-level permissions across your key pages for that mismatch, including a Configuration or Preferences permission left open to a role that should only see the widget’s View output.
Documents and Media Access Control
Documents and Media separates folder-level permissions such as Access, Add Document, Add Subfolder and Delete from repository-level permissions such as Add Repository and Add Metadata Set, so a role can hold one without the other. We test folder and repository permissions together, looking for a role that can add or delete content in a folder it was only meant to view, or a Guest-level Access grant left on a folder that should require sign-in.
JSON Web Services and Service Access Policies
Liferay’s headless REST APIs and JSON web services require authentication by default, and a Service Access Policy set up in Control Panel, Security, Service Access Policy is the control that opens a specific method to unauthenticated requests instead. We test which service access policies exist on your instance, what method each one exposes, and whether any grant Guest access wider than the one endpoint they were written for.
Headless REST and GraphQL API Authorisation
Where headless REST APIs sit behind authentication, we test object-level access the same way we would on any API, an authenticated request for a record it should not reach. Liferay’s own documentation flags that a Service Access Policy cannot discriminate within the GraphQL endpoint the way it can for individual REST resources, so we test GraphQL access separately rather than assume it inherits the same restrictions as the REST equivalent.
Custom OSGi Modules and Local Service Calls
Liferay’s own documentation on the Script Console confirms permission checking is not enforced for local services, the same service layer a custom OSGi module can call directly. We review custom OSGi modules for logic that calls a local service without re-implementing the permission check a portlet or headless endpoint would normally apply.
Groovy Script Console Access
The Script Console runs Groovy directly against your instance, and Liferay’s own documentation states there is no undo, no preview, and that permission checking is not enforced for the local services a script calls. Liferay recommends limiting access to portal administrators, so we check who can reach it and confirm it is not left open to a wider group.
Liferay SaaS, PaaS and Self-Hosted Deployment Surface
Liferay SaaS restricts customisation to client extensions running in a separate environment, while Liferay PaaS and self-hosted deployments give you the Liferay Workspace and OSGi module tooling Liferay itself uses. Which model you run changes what is in scope: SaaS testing stays inside your Liferay configuration and client extensions, while PaaS and self-hosted testing extends to custom OSGi modules and, on self-hosted, the underlying Java, Tomcat and database layer our wider Java and Spring testing covers.
OUR PROCESS
Liferay Penetration Testing: From Scope to Attestation
Scope and Access
We agree which Sites, Organisations and instances are in scope, plus the accounts we need for every Regular, Site and Organisation role in use, including a Guest-level view of every public page.
Permission and Scope Mapping
We map your Regular, Site and Organisation roles and custom roles against Liferay’s default roles reference, document every Service Access Policy, and note where a mapping grants more than its scope implies.
Manual Testing
A CREST-certified tester manually exploits gaps in role scope, Guest access, portlet and widget permissions, Documents and Media folders and headless API authorisation, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Liferay pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Liferay Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
3 to 4 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote6 to 9 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Liferay For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Liferay Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Liferay instance?
We need at least one authenticated account for every Regular, Site and Organisation role in scope, including a Site Administrator or Organisation Administrator account where those exist, plus an administrator account with access to Control Panel security settings if Service Access Policies or the Script Console are in scope. For headless API testing we need valid credentials for each permission tier you have defined.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk changes through Documents and Media, edits to live Service Access Policies and use of the Script Console against production data, and we do not run destructive tests against real records without that agreement in writing.
How long does a Liferay penetration test take?
A single Liferay instance with one or two Sites sits in our 3-day single-framework scope, with a report typically landing around 5 to 8 working days after kickoff. An instance with many Organisations, a large custom OSGi codebase or a wide headless API surface moves into a broader scope with more testing days.
Do you test Liferay SaaS and PaaS the same way as self-hosted?
The role, permission, portlet and API testing is the same across Liferay SaaS, PaaS and self-hosted deployments. Liferay SaaS restricts customisation to client extensions, so custom OSGi module review and Script Console access apply to PaaS and self-hosted instances rather than SaaS, and self-hosted also brings the underlying Java, Tomcat and database layer into scope if you want it tested.
What is out of scope for a single-framework Liferay test?
Infrastructure-level issues in the underlying server, network or cloud configuration are out of scope for this test and covered by our cloud penetration testing service instead. A separate frontend application consuming Liferay’s headless APIs, such as a decoupled React or Vue app, is also scoped and quoted separately.
Do you need our source code or access to custom OSGi modules?
No. Testing is black-box against the running instance by default. A grey-box option, where we review custom OSGi module source and Service Access Policy configuration alongside testing, is available if you want faster or deeper coverage of specific findings.
Is the Script Console in scope by default?
Only if you tell us it exists and give us access. The Script Console runs Groovy against your live instance with no undo, so we agree in scoping whether we test who can reach it or whether you want it excluded from testing entirely.
Does Liferay have a customer penetration-testing policy we need to follow?
It depends on your deployment. Testing a self-hosted Liferay instance is testing infrastructure you control, so there is no Liferay vendor process to follow for that layer. If you run Liferay SaaS or PaaS, Liferay’s own infrastructure sits underneath your instance, so we confirm Liferay’s current terms for customer testing during scoping rather than assume they are unchanged.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Liferay instance
One Liferay instance can run many Sites and Organisations, and a role granted at the wrong scope crosses between them. We test whether Site, Organisation and Guest permissions hold that boundary. CREST-certified testers, fixed price from £3,480 for a 3-day single-framework scope, quoted within 24 hours.



