TECHNOLOGIES: STRAPI

Strapi Penetration Testing for Roles, Tokens and Plugin Security

Strapi gives you a permissions plugin, an admin panel and a token system out of the box, and most Strapi findings come from how those pieces get configured rather than a flaw in the CMS itself. We test the role boundaries your team set in the Users and Permissions plugin, the API tokens and JWTs guarding your content API, and the custom controllers, policies and middlewares your developers added on top. CREST-certified testers, fixed price from £2,540 for a 2-day single-platform scope, quoted within 24 hours.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
CREST
Approved Provider
10
Strapi Test Areas
FREE
Retest Until Closed
24h
Scope to Active Test
CLIENT REFERENCE
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
SquareOneImran SaghirProject Lead, SquareOneRead the SquareOne case study →
CLIENT REFERENCE
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
CelloriDan WilcocksonFounder, CelloriRead the Cellori case study →
See all case studies →
WHY IT MATTERS
Public

Any request to a Strapi API without a token is treated as the Public role. Every permission ticked for Public, even briefly during development, is open to anyone on the internet.

Why Strapi findings are usually a permission, not a platform flaw

Strapi’s Users and Permissions plugin ships two default end-user roles, Public and Authenticated, and every content type, custom route and plugin action is switched on or off per role from a single permissions table. Strapi’s own documentation confirms that any request without a token assumes the Public role’s permissions by default, so a box left ticked during development stays reachable by anyone once the project ships. We test what Public and any custom roles can actually reach against what the application is meant to expose.

The admin panel runs on its own authentication and role model entirely separate from end-user accounts, with Author, Editor and Super Admin as the default administrator roles and a permissions table covering every content type, plugin and setting. Alongside it sit API tokens for external integrations, Read-only, Full access or Custom in scope, each with its own duration, and JWTs for end-user sessions whose expiry and secret strength we check against what Strapi recommends. Both are common places for scope to drift wider than the integration that needed it.

Custom code is the third layer. A controller that overrides a core action without the query validation and output sanitisation Strapi’s documentation calls for can hand back fields the role permissions were meant to hide, and a policy or middleware wired to the wrong route can gate the wrong thing, or nothing at all. We test the plugin configuration and custom code you have added, not the open-source core underneath it.

SCOPE

What we pen test on a Strapi instance

ST-01

Public and Authenticated Role Boundaries

Every content type, custom route and plugin action is switched on or off per role in the Users and Permissions plugin, and Strapi treats any request without a token as the Public role. We test what Public and Authenticated can each reach against what your front end actually needs them to reach.

ST-02

Custom End-User Roles and Permission Drift

Roles beyond the two defaults are configured the same way, and deleting a role automatically reassigns its users to Public rather than leaving them unassigned. We test for permission sets copied from a broader role and never trimmed, and for what actually happens to access when a role is removed.

ST-03

REST and GraphQL API Authorisation

The same Users and Permissions checks are meant to cover the REST and GraphQL content APIs equally, and we test whether GraphQL resolvers and field-level access on relations enforce what the REST routes already restrict.

ST-04

JWT and Session Configuration

We check the JWT secret and its expiry, and whether the project runs Strapi’s legacy long-lived token mode or the newer refresh-token session mode, plus whether an end user can list and revoke their own active sessions where that mode is enabled.

ST-05

API Tokens and Scope

Every active API token is reviewed for its type, Read-only, Full access or Custom, its duration and where it lives in your integrations, since a Full access token dropped into a script carries far more reach than the integration needs.

ST-06

Admin Panel Separation and Admin RBAC

The admin panel authenticates administrators separately from end users, with Author, Editor and Super Admin as the default roles and their own permission table across every content type, plugin and setting. We test that the two systems never cross and that each admin role reaches only what it should.

ST-07

Uploads and the Media Library

Upload validation, the permission required to reach the media library itself, and, where a private storage provider is configured, whether signed URLs and their expiry genuinely restrict access to what has been uploaded.

ST-08

Custom Controllers and Services

Overridden core actions and bespoke controllers are checked against the query validation and output sanitisation Strapi’s own documentation recommends, since skipping it is exactly what lets a custom endpoint return fields the role permissions were meant to hide.

ST-09

Policies and Middlewares

Custom policies that are meant to gate a route before it reaches a controller, and custom middlewares that touch the request or response, tested for logic that fails open, applies to the wrong scope, or never runs at all.

ST-10

Self-Hosted Infrastructure vs Strapi Cloud

Self-hosted, your server, database and file storage sit in scope alongside the application and its configuration. On Strapi Cloud the platform itself is managed by Strapi, so testing concentrates on the content types, roles, tokens and custom code you control.

OUR PROCESS

Strapi Penetration Testing: From Scope to Attestation

01

Scope and Role Mapping

We agree the environments, accounts and roles in scope, and map every content type, custom route, plugin, policy and API token in the instance before testing begins.

02

Automated and Role-Based Scanning

Authenticated and unauthenticated scanning across every role, Public included, plus targeted checks against known Strapi configuration weaknesses.

03

Manual Exploitation

A CREST-certified tester manually tests permission boundaries, token scope, custom controller and policy logic, chaining findings where they compound.

04

Reporting and Retest

You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get a CREST Strapi pen test quote in 24 hours

A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonFounder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
  1. We reply within one business day with a fixed-price quote from a named CREST assessor.
  2. You approve the scope and we book a start date, usually within 24 hours.
  3. Live findings land in your client portal as we test, with a free retest of every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed pen test quote in 24 hours

⚡24h reply ✓CREST tester ↻Free retests

or book a 20-min scoping call first

We reply within one business day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are written so your team can reference the report against each framework without translation work.

ISO 27001:2022

Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.

SOC 2 Type I & II

CC6 logical access, CC7 system operations, CC8 change management evidence.

PCI DSS

Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.

FCA SYSC

SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.

UK GDPR

Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.

Cyber Essentials Plus

Direct certification through our IASME body status, single-vendor delivery.

PRICING

Transparent Strapi Penetration Testing Pricing

Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
✓Free retests, no time limit
✓Free rescheduling
✓No cancellation fees
✓24-hour scope to active testing
✓Live findings to client portal
✓Executive + technical report
✓60-min walkthrough call
✓Letter of attestation
SMALL / SMB
£2,540–£3,730
2 to 3 testing days

Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.

Get a fixed quote
ENTERPRISE
£5,970–£9,090
5 to 7 testing days

Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.

Get a fixed quote

Full UK pen test cost guide

WHY EJN LABS

What You Get From Strapi Penetration Testing

Six concrete differentiators competitors don’t all match.

CREST-Certified Testers, Verifiable

Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.

24-Hour Startup, Where Required

From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.

Live Findings, Not 4-Week PDFs

Critical issues reported during testing through your client portal. Your team remediates while testing continues.

Audit-Ready Reports

Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).

Free Retests, Standard

Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.

UK-Based CREST Testers

Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.

FAQ

Frequently Asked

What access do you need to test our Strapi instance?

An admin account with a role you control, so we see the same permission structure your team manages day to day, plus at least one Public-role and one Authenticated-role end-user credential to test the boundary between them. Visibility of any custom controllers, policies or middlewares in the codebase speeds up coverage but is not required for black-box testing.

Does this touch our live data?

No. We test against a staging environment or a cloned copy of your content wherever one exists. Where only production is available, any check that could affect real data is agreed and scoped in advance, and read-only checks are logged as they happen.

How long does a Strapi penetration test take?

A single-platform Strapi engagement is scoped at 2 testing days as a starting point, rising with the number of content types, custom plugins and roles in play. Reporting and a walkthrough call follow testing, with a free retest once fixes are in.

Is self-hosted Strapi tested differently from Strapi Cloud?

Yes. Self-hosted, your server, database and file storage are in scope alongside the application and its permissions. On Strapi Cloud the underlying platform is managed by Strapi, so testing concentrates on your content types, roles, API tokens and custom code.

What is out of scope?

The Strapi core codebase itself, since that is Strapi’s platform to secure rather than something your configuration changes. Third-party plugins you have not installed, and any infrastructure outside the Strapi application, unless you scope a wider cloud or network review alongside it.

Does Strapi have a policy for reporting security issues?

Strapi runs a responsible disclosure programme for its own platform: vulnerabilities in Strapi core are reported through GitHub Advisory or to security@strapi.io, and the team works with researchers to patch before public disclosure. That covers issues in Strapi itself, not the roles, tokens, permissions and custom code you have configured, which is what this engagement tests. If you run on Strapi Cloud, we check Strapi’s current terms with you during scoping before any testing starts.

Do you test GraphQL as well as REST?

Yes, where GraphQL is enabled. It exposes the same content types through a different endpoint and query language, so we test each one rather than assuming coverage carries over from REST.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get a fixed price for your Strapi instance

Strapi gives you a permissions plugin, an admin panel and a token system out of the box, and most Strapi findings come from how those pieces get configured rather than a flaw in the CMS itself. We test the role boundaries your team set in the Users and Permissions plugin, the API tokens and JWTs guarding your content API, and the custom controllers, policies and middlewares your developers added on top. CREST-certified testers, fixed price from £2,540 for a 2-day single-platform scope, quoted within 24 hours.