Case Study: Aromatic Scents Lab – Web Application Security Assessment

12

Security findings

50+

Functional and UX defects

3

Platforms covered

Overview

Aromatic Scents Lab (ASL) is a bilingual, multi-currency headless eCommerce platform for premium fragrances, built on a Next.js frontend with a WooCommerce/WordPress backend. Serving customers across the GCC in both English and Arabic (with full RTL support) and pricing in seven currencies, ASL needed assurance that its platform could handle real-world purchase behavior, regional payment methods, and device diversity — without exposing the business to security risk as it scaled.

Testvox ran a combined engagement covering functional and cross-platform QA alongside a full OWASP-aligned security assessment, giving ASL a single, prioritized view of both product-quality and security risk ahead of launch.

Challenges ASL Faced

Before the engagement, ASL faced three categories of risk:

  • Purchase-flow blockers on live-critical paths Card payments were failing outright, preventing full order validation; the wishlist could be used without login, undermining account-based personalization; and on Android specifically, users couldn't add products to cart at all — a full stop on the primary conversion path for that platform.
  • Cross-platform and cross-browser consistency With a bilingual (EN/AR, LTR/RTL), multi-currency storefront running across desktop and mobile Safari, Chrome, and Samsung Browser, ASL needed every core module — catalog, cart, checkout, reviews, wishlist, account — validated consistently across environments, not just on a single reference device.
  • Security exposure on a live headless architecture - **Security exposure on a live headless architecture.** With payment processing (MyFatoorah, Tabby, Tamara), JWT-based authentication, and a WooCommerce data layer handling customer PII, ASL needed a genuine black-box penetration test — not just a plugin-update checklist — to know where an attacker could actually get in.

Testvox Solution

In order to tackle these challenges, a systematic and risk-oriented remediation strategy was put into action:

  1. End-to-End Functional & Cross-Platform Testing
  2. Testvox validated every core module — login/registration, product catalog, cart, checkout, brands/tags/attributes, reviews, wishlist, and payments — across both frontend and admin, on desktop and on iPhone and Android across multiple browsers. Each defect was logged with severity, reproduction steps, and platform context so the dev team could triage by real-world impact rather than guesswork.

  3. OWASP-Aligned Security Assessment
  4. Testvox's security team ran a black-box penetration test against the ASL staging and production web applications, combining automated scanning (WPScan, testssl.sh, Nmap) with manual verification against the OWASP Web Security Testing Guide and OWASP Top 10 — covering authentication and session handling, API and payment-adjacent data exposure, TLS/server configuration, and outdated dependencies.

  5. Risk-Ranked Remediation Roadmap
  6. Rather than handing over a flat findings list, Testvox delivered a prioritized roadmap — Immediate, Sprint, and Planned — so ASL's team knew exactly what to fix before the next release versus what could be scheduled. A structured retesting cycle followed each round of fixes, with full sign-off reserved until all reported issues were verified closed.

Result

Purchase-Blocking Bugs Caught Before Customers Were

Critical issues — non-functional card payments, an authentication gap on wishlist, and an Android add-to-cart failure — were identified and escalated before they could affect real transactions, protecting both revenue and customer trust.

A Clear, Prioritized Security Roadmap

Twelve findings, including high-severity issues in authentication and infrastructure exposure, were delivered with CVSS scoring, OWASP/CWE mapping, and concrete remediation steps — giving ASL's team an actionable path rather than a raw vulnerability dump.

Confidence Across Devices, Browsers, and Languages

With coverage spanning EN/RTL Arabic layouts, multiple currencies, and desktop plus iOS/Android browsers, ASL gained a platform validated the way real customers actually use it — not just on a single happy-path environment.

Conclusion

By pairing structured functional and cross-platform QA with a genuine OWASP-based security assessment, Testvox gave Aromatic Scents Lab a single, prioritized view of where the platform needed to harden before scaling — across purchase flows, device coverage, and application security alike.

Related Resources