Consumer Internet
Source Code Review of an Internationally Renowned MNC
At a glance
INDUSTRY
Consumer Internet
CLIENT PROFILE
A global multinational conglomerate present in 100+ countries across 6 continents, launching an all-in-one digital platform
SERVICES
Secure Source Code Review
ENGAGEMENT
Pre-launch source code review across the platform, its acquisitions, and a third-party CMS

key Numbers
5,00,000+
100+
5
Key Takeaways
Client – A global multinational conglomerate with a presence in 100+ countries across 6 continents, weeks away from launching an all-in-one digital platform for Indian consumers and businesses.
Problem – The client needed its platform source code, newly acquired businesses across electronics, lifestyle, FMCG, grocery, hospitality, and a third-party CMS reviewed for vulnerabilities before launch, within a tight deadline.
What Payatu did – We reviewed 5,00,000+ lines of Java and JavaScript, walked through the codebase and test plans, ran automated tools with manual validation, and extended the review to the third-party CMS added mid-engagement.
Outcome – The client received a report of exploitable issues, hardcoded sensitive information, a misconfigured AndroidManifest, insecure communication and logging, and a vulnerable module, with remediation guidance to address them before launch.
the challenge
Why the client called us in
Our client, a global multinational conglomerate built on decades of reputation, was weeks away from launching a single digital platform that would fold in all of its consumer-facing services for Indian customers and businesses. The platform combined code from the client's own applications with code from multiple newly acquired companies spanning electronics, lifestyle and apparel, FMCG, grocery delivery, and hospitality, plus a third-party CMS. With over 5,00,000 lines of Java and JavaScript to secure and a fixed launch date, the client needed an independent source code review to catch issues before they shipped.
- Review the source code of the core platform and all acquired-company modules
- Run tooling to catch known vulnerabilities in third-party components
- Deliver findings and fixes in time for the platform's launch deadline
scope of engagement
What was in scope
- Reviewing the code of the client's core applications
- Reviewing the code of acquired enterprises across electronics, lifestyle and apparel, FMCG, grocery delivery, and hospitality
- Reviewing 5,00,000+ lines of Java and JavaScript code
- Reviewing the code of the client's third-party CMS
- Running tools against third-party modules to check for known vulnerabilities
Our Approach
How Payatu ran the engagement
01
02
03
04
05
Key findings
What we found
the outcome
Results and Impact
The review gave the client a clear, prioritized map of the vulnerabilities inside its new digital platform, its acquired-company modules, and its third-party CMS, each explained with technical impact, business impact, and remediation steps. Delivered inside the client's launch window despite a mid-project scope increase, the findings let the security team fix the highest-impact issues before the platform went live.
Over 5,00,000 lines of Java and JavaScript code reviewed across the platform and its acquisitions
Third-party CMS brought into scope and reviewed within the original deadline
Five categories of exploitable issues identified with business impact and remediation guidance
Recommendations delivered on endpoint authentication, role-based authorization, and third-party module hygiene
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







