TECHNOLOGIES: REACT NATIVE

React Native Penetration Testing

A React Native app ships its JavaScript bundle to every device, so its logic and secrets are there to read. We test the bundle, the native bridges and how tokens are stored. CREST-certified testers, fixed price from £4,240 for a 3-day single-framework scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
React Native Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Readable

React Native ships your JavaScript logic to the device as a bundle, and Meta’s own guidance is explicit that anything hardcoded in it, including API keys, can be read in plain text. We test what the bundle and the native bridge around it actually expose.

Why React Native risk sits at the boundary between JavaScript and native code

Every React Native app ships its JavaScript logic inside the installed bundle rather than on a server you control, and where Hermes is enabled that bundle runs as compiled bytecode rather than plain JavaScript. Meta’s own React Native security documentation is explicit that anything hardcoded in your code, including API keys, can be read in plain text by anyone inspecting the app bundle. We extract the bundle and the Hermes bytecode and review both for hardcoded secrets, business logic that belongs on a server, and endpoints or feature flags the interface does not otherwise reveal.

Native modules and Turbo Modules cross the JSI bridge into platform code that a JavaScript-side check cannot see, so an authorisation rule written only in JavaScript is not enforced once a native module is called directly. React Native’s own security guidance cautions against letting sensitive data end up in Async Storage and confirms that Android’s Shared Preferences are not encrypted by default, recommending a Keychain or Keystore wrapper such as Expo SecureStore or react-native-keychain instead. We test what each native module exposes across the bridge and whether tokens, session data and credentials actually sit behind Keychain or Keystore rather than in Async Storage.

Deep links and universal links give any app on the device a way to open your screens directly, and because a mobile URL scheme is not guaranteed unique the way a web origin is, React Native’s guidance recommends the PKCE extension for any OAuth flow that finishes through a redirect. Apps that ship updates over the air through Expo Updates or a similar channel bypass app store review for that code, and Expo’s own documentation describes verifying every downloaded update against an embedded certificate and signature before it is applied, rejecting it otherwise. We test your deep link handlers, your update channel’s signing configuration, certificate pinning and how the backend behind the app enforces access, since a client-side check is only ever a convenience. Findings map to the storage, network, platform and resilience categories in OWASP’s Mobile Application Security Verification Standard.

SCOPE

What we pen test on a React Native application

RX-01

JavaScript Bundle and Hermes Bytecode Exposure

The installed app ships your JavaScript logic and, where Hermes is enabled, its compiled bytecode, inside the bundle rather than on a server you control. We extract the bundle and review it for hardcoded API keys, signing secrets and business logic that should sit behind your backend instead.

RX-02

Native Module and JSI Bridge Boundary

Turbo Modules and the JSI bridge call platform code directly, so an authorisation check written only on the JavaScript side is not enforced if a native module is called another way. We test what each bridge method actually exposes and whether native code re-checks the same permissions the JavaScript layer assumes.

RX-03

Token and Credential Storage

React Native’s own security guidance cautions against letting sensitive data end up in Async Storage and confirms that Android’s Shared Preferences are not encrypted by default. We check whether tokens, session data and credentials actually sit behind Keychain on iOS or Keystore on Android, through a wrapper such as Expo SecureStore or react-native-keychain, rather than in Async Storage.

RX-04

Deep Link and Universal Link Handling

A mobile URL scheme is not guaranteed unique the way a web origin is, so another app can register the same scheme and intercept a link meant for yours, including an OAuth redirect. We test your deep link and universal link handlers for parameter validation, redirect hijacking and whether authentication flows use the PKCE extension.

RX-05

Over-the-Air Update Signing

Updates delivered over the air through Expo Updates or a similar channel bypass app store review for that code, so the update channel itself becomes a route into the app if it is not locked down. We check whether code signing is configured so an unsigned or tampered update is rejected rather than applied.

RX-06

WebView Configuration and Bridge Exposure

A WebView that loads untrusted content or exposes a JavaScript bridge to the native side can let web content reach native functionality it should never touch. We test what your WebView loads, what origins it allows and what the JavaScript bridge lets a web page call.

RX-07

Certificate Pinning and Transport Security

Without certificate pinning, a device on a compromised network or with a rogue root certificate installed can intercept traffic between the app and your API, even over HTTPS. We test whether certificate pinning is implemented correctly and whether your rotation plan avoids the app breaking when a pinned certificate expires.

RX-08

Backend Authorisation Behind the App

A check written into the app is a convenience, not a control, since anyone can rebuild the request without the app in between. We test whether your backend enforces authorisation and object-level access itself, independent of what the React Native client sends or withholds.

RX-09

Debug Bridge and Development Tooling

Debugging tools and remote JavaScript inspection are built for development and can expose app state, network traffic or the bridge itself if a build ships with them still reachable. We check whether debug tooling, remote debugging and development-only endpoints are actually disabled in the build you release.

RX-10

Shared JavaScript and React Code

Where a React Native app shares business logic, API clients or a component library with a React web app, a flaw in that shared code reaches both surfaces. If your organisation also runs a separate React frontend, our React penetration testing covers it alongside this scope.

OUR PROCESS

React Native Penetration Testing: From Scope to Attestation

01

Scope, Builds and Access

We agree which builds, environments and backend endpoints are in scope, plus the test accounts, API tokens and any TestFlight, Play internal track or debug build access we need.

02

Bundle and Bridge Mapping

We extract the JavaScript bundle, map every native module and Turbo Module exposed across the bridge, and identify where deep links, OTA updates and third-party SDKs sit in the build.

03

Manual Testing

A CREST-certified tester manually exploits weaknesses in storage, bridge exposure, deep link handling, certificate pinning and backend authorisation, chaining findings where they compound.

04

Attestation and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST React Native pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent React Native Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£4,240–£5,780
3 to 5 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£8,190–£11,240
7 to 9 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From React Native Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our React Native app?

We need the app build itself, ideally through TestFlight, a Play internal testing track or a signed APK or IPA, plus at least one authenticated account for every distinct role in the app. If the app calls a backend you control, we also need API documentation or a schema export, and any tokens needed to reach staging or a dedicated test environment.

Will testing touch our live data?

We test whichever build and environment you give us access to. If that points at production, we agree exclusions upfront, such as destructive account actions, real payment processing and outbound notifications, and we do not run those tests against live customer data without that agreement in writing.

How long does a React Native penetration test take?

A single React Native application sits in our 3-day single-framework scope, with a report typically landing around 5 working days after kickoff. An app with more roles, a larger native module surface or multiple backend integrations moves into a wider scope with more testing days.

Do you test Expo apps as well as bare React Native projects?

Yes. We test apps built with Expo, including Expo Updates and SecureStore usage, the same way as a bare React Native project with custom native modules. The native bridge and build tooling differ, but the JavaScript bundle, storage and network testing is the same either way.

Is the backend our app calls included in the test?

Only if you scope it in. This test covers the React Native app itself, its bundle, native bridge, storage and update channel. Testing the API or backend behind it in depth is covered by our API penetration testing and can be scoped alongside this test.

What is out of scope for a single-framework React Native test?

Infrastructure hosting your backend, such as your cloud environment or servers, is out of scope for this test and covered by our cloud penetration testing service instead. A separate web app or admin panel sharing the same backend is also scoped and quoted separately.

Do you need our source code?

No. Testing is black-box against the installed app and its bundle by default. A grey-box option, where we review the native module code, bridge implementations and update signing configuration alongside testing, is available if you want faster or deeper coverage of specific findings.

Does React Native or Expo have a customer penetration-testing policy we need to follow?

React Native and Expo are open-source tooling you build, sign and release yourself rather than a shared multi-tenant service, so there is no vendor notification process for the app itself. If your app relies on a backend platform, an MBaaS, or a distribution channel such as the App Store, Google Play or an OTA update provider, we confirm that provider’s current testing terms during scoping.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your React Native application

A React Native app ships its JavaScript bundle to every device, so its logic and secrets are there to read. We test the bundle, the native bridges and how tokens are stored. CREST-certified testers, fixed price from £4,240 for a 3-day single-framework scope, quoted within 24 hours.