In-depth penetration testing for marketplaces that need to isolate sellers, validate splits and stop seller-to-seller fraud.

Offensive security assessments built for marketplaces (e-commerce, services, food delivery, mobility). Full coverage of payment splits, commission tampering, seller-to-seller fraud, payout race conditions, anti-fraud controls and tenant isolation. The same methodology our researchers use in international bug bounty programs.

  • Mutual NDA within 24h
  • Retest included
  • Direct contact with the researcher

Why marketplaces

A marketplace has three parties — and a bug in any relationship becomes fraud

In a typical SaaS, the risk model is simple: one customer can't see another customer's data. In a marketplace, the model is a triangle:

  • Buyer → Seller — a buyer can't see other buyers' data; a seller can't see data from buyers who aren't theirs
  • Seller → Seller — seller A can't read or edit seller B's products, orders or financials
  • Platform → Seller (financials) — splits, commissions, pending balances and early settlement can't be manipulated by the seller

Each corner of that triangle has its own bug pattern. A marketplace that gets attacked is usually attacked through a compromised seller account, or one created for fraud — a vector a typical B2B SaaS doesn't even need to model.

Scope

What our marketplace penetration testing covers

Seller isolation (cross-seller)

  • BOLA — seller A sees seller B's orders, products and financials
  • BOLA on upload endpoints (another seller's images)
  • Cross-seller access via search/filter endpoints
  • Cache poisoning between sellers (CDN, Redis)
  • Leaks via webhooks sent to another seller
  • Namespacing bypass in integrations (ERP, marketplace-of-marketplaces)

Payment splits and commissions

  • Split manipulation (a seller receives a higher percentage than configured)
  • Commission bypass through payload modification at checkout
  • Race conditions in fund distribution between marketplace and seller
  • Order manipulation after the split has been processed
  • Replay of sub-acquirer webhooks (PagSeguro, Mercado Pago, Stripe Connect)
  • Sub-acquiring manipulation (splits across multiple sellers in 1 order)

Payouts and early settlement

  • Payout race conditions (double withdrawal)
  • Payout amount vs. actual balance manipulation
  • Payee validation bypass on Pix, Brazil's instant payment system (payouts to a third party's account)
  • Early settlement of receivables — fee manipulation, flow abuse
  • Holding period bypass

Anti-fraud and moderation

  • Risk score bypass through fingerprint modification
  • BOLA on the anti-fraud rules endpoint (rule dump)
  • Moderation status manipulation (self-approval)
  • Seller KYC validation bypass
  • Selfie/document reuse to create multiple accounts

Seller dashboard (seller center)

  • BFLA on administrative endpoints
  • BOPLA — editing private fields (balance, fees, commission)
  • Mass assignment on product updates
  • CSV/PDF/XML injection in exports and reports
  • SSRF via configurable ERP integrations
  • Path traversal in tax invoice downloads

Ratings, reviews and disputes

  • BOLA — editing another seller's review
  • Rating manipulation through bulk requests
  • Review moderation bypass (HTML injection, stored XSS)
  • Fraudulent disputes — evidence abuse
  • Replying to reviews as a fake seller

Logistics and shipping

  • Shipping cost manipulation (changing the amount after the order is placed)
  • ZIP/postal code or region validation bypass
  • BOLA on the tracking endpoint
  • Cross-seller leaks via carrier webhooks
  • Status manipulation (marking an order as delivered without shipping it)

Coupons, vouchers and cashback

  • Reuse of single-use coupons
  • Combining mutually exclusive coupons
  • Eligibility rule bypass (tax ID, first order)
  • Race conditions on quantity-limited coupons
  • Cashback manipulation on cancellations

Pricing

Marketplace penetration testing pricing

ScenarioPrice rangeCoverage
Early-stage marketplace (up to 100 sellers)Sprint (25h): US$ 3,750 to US$ 6,250Web + API + isolation + basic splits
Marketplace in production (1K+ sellers)Deep Dive (50h): US$ 7,500 to US$ 12,500+ seller dashboard + anti-fraud + payouts
Enterprise marketplace (food delivery, mobility)Full Scope (100h+): from US$ 15,000White box + mobile + integrations + ML anti-fraud
Recurring, sprint-alignedPTaaS: on requestContinuous pentesting + monitoring of new sellers

Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

FAQ

Frequently asked questions

  • What makes marketplace penetration testing different?

    A marketplace has three parties: buyer, seller and platform. A bug in any relationship between them becomes a problem. BOLA between sellers (seller A sees seller B's orders), split manipulation (a seller receives a higher percentage than configured), commission bypass, payout race conditions and seller-to-seller fraud are patterns specific to marketplaces that don't show up in a typical SaaS.

  • Do you cover payment splits?

    Yes. Coverage includes split manipulation between the marketplace and the seller, race conditions in fund distribution, commission bypass through payload modification, replay of sub-acquirer webhooks, manipulation of pending balances and abuse of early settlement of receivables.

  • How much does marketplace penetration testing cost?

    Early-stage marketplace (up to 100 sellers): Sprint (25h), US$ 3,750 to US$ 6,250. Marketplace in production (multi-category, 1K+ sellers): Deep Dive (50h), US$ 7,500 to US$ 12,500. Enterprise marketplace (Mercado Libre-style, food delivery, mobility): Full Scope (100h+), from US$ 15,000. PTaaS (recurring): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.

  • Do you also test the seller dashboard?

    Yes. The seller dashboard (seller center) is where most cross-seller bugs happen — because that's where sellers can run bulk actions: product edits, exports, ERP integrations, shipping settings. Full coverage of the dashboard is part of the standard scope.

Next step

Request a proposal for your marketplace.

Mutual NDA within 24h. Once it's signed, a technical call to map your split flow, sellers and anti-fraud controls. Formal proposal within 3 business days.

Talk to a researcher