Get in Pole position with MAYFLOWER

Chorizo! Security Audits

The number of mission critical enterprise applications in the internet grows on a steady base. There is online banking, which is used intensely by banking customers, web shops, offering nearly everything to internet users and booking engines for flights and hotels to just name a few.

All of these applications need to be easy to use and they need to be safe against third party attacks.

But Independent studies show that 69% of todays security vulnerabilities could be found in web applications.

This is a critical issue for a lot of companies, as the secure communi-cation with the users is a key element of their commercial success.

With a wide range of security products MAYFLOWER enables you to make your web applications secure.

Next to our well known security scanner Chorizo!, a tool which helps you to close all commodity security vulnerabilities of your applications right from the start, MAYFLOWER offers individual security audits, to fully screen your application.

Chorizo! PenTest

Chorizo! PenTest works with common injection vectors normally used in attacks against web applications. This kind of testing does not involve the screening of your source code, but our security consultants check the security of your application from the outside.

Chorizo! Standard Audit

The Chorizo! Standard Audit makes it possible to secure your source code against vulnerabilities with a reasonable financial effort.

Our Security-Consultants audit selective samples directly from the applications source code and check fort he classical injection vectors. Included are checks for:

  • Code Inclusions
  • Code Executions
  • SQL-Injections
  • Cross Side Scripting
  • and more

Chorizo! Extended Audit

The Chorizo! Extended Audit includes all tests performed in the standard audit, but also a complete source-code audit, where every critical function call is individually analyzed.

Especially customers with applications in company critical environments should see this full code audit as an essential part of development and operation.

Additional to the standard tests the screening of client security is also a part of the extended audit. Tests for:

  • JavaScript Inclusions (XSS)
  • Cross Side Request Forging


will be performed too. And finally the complete application will be screened for logical vulnerabilities.