Research Library / Case Studies /

Consumer Internet

Source Code Review of an Internationally Renowned MNC

A global MNC preparing to launch an all-in-one digital platform for Indian consumers and businesses asked us to review the source code of its core applications, its acquired-company modules, and its third-party CMS before go-live. We reviewed over 5,00,000 lines of Java and JavaScript code across the platform and its acquisitions.
Secure Source Code Review

At a glance

INDUSTRY

Consumer Internet

CLIENT PROFILE

A global multinational conglomerate present in 100+ countries across 6 continents, launching an all-in-one digital platform

SERVICES

Secure Source Code Review

ENGAGEMENT

Pre-launch source code review across the platform, its acquisitions, and a third-party CMS

key Numbers

5,00,000+

Lines of Code Reviewed

100+

Countries of Client Presence

5

Vulnerability Categories Flagged

Key Takeaways

  • Client – A global multinational conglomerate with a presence in 100+ countries across 6 continents, weeks away from launching an all-in-one digital platform for Indian consumers and businesses.

  • Problem – The client needed its platform source code, newly acquired businesses across electronics, lifestyle, FMCG, grocery, hospitality, and a third-party CMS reviewed for vulnerabilities before launch, within a tight deadline.

  • What Payatu did – We reviewed 5,00,000+ lines of Java and JavaScript, walked through the codebase and test plans, ran automated tools with manual validation, and extended the review to the third-party CMS added mid-engagement.

  • Outcome – The client received a report of exploitable issues, hardcoded sensitive information, a misconfigured AndroidManifest, insecure communication and logging, and a vulnerable module, with remediation guidance to address them before launch.

the challenge

Why the client called us in

Our client, a global multinational conglomerate built on decades of reputation, was weeks away from launching a single digital platform that would fold in all of its consumer-facing services for Indian customers and businesses. The platform combined code from the client's own applications with code from multiple newly acquired companies spanning electronics, lifestyle and apparel, FMCG, grocery delivery, and hospitality, plus a third-party CMS. With over 5,00,000 lines of Java and JavaScript to secure and a fixed launch date, the client needed an independent source code review to catch issues before they shipped.

  • Review the source code of the core platform and all acquired-company modules
  • Run tooling to catch known vulnerabilities in third-party components
  • Deliver findings and fixes in time for the platform's launch deadline

scope of engagement

What was in scope

  1. Reviewing the code of the client's core applications
  2. Reviewing the code of acquired enterprises across electronics, lifestyle and apparel, FMCG, grocery delivery, and hospitality
  3. Reviewing 5,00,000+ lines of Java and JavaScript code
  4. Reviewing the code of the client's third-party CMS
  5. Running tools against third-party modules to check for known vulnerabilities

Our Approach

How Payatu ran the engagement

01

Code Walkthrough
Walked through the codebase to understand its structure and map out the review.

02

Test Plan Preparation
Built a test plan and followed the code routes manually to plan the review path module by module.

03

Automated and Manual Validation
Ran tooling as part of the review automation to surface findings, then manually validated each one.

04

Recording Findings
Logged validated findings for reporting.

05

Reporting
Wrote up each finding with its description, technical impact, business impact, criticality, and remediation guidance.

Key findings

What we found

Data Exposure
Sensitive information was hardcoded directly into the application source instead of pulled from a secure secrets store.
Mobile Configuration
The Android application's manifest file was misconfigured, widening the app's attack surface.
Communication Security
Portions of the platform communicated over channels that did not adequately protect data in transit.
Logging Practices
The application logged data insecurely, risking exposure of sensitive information through log files.
Third-Party Components
Automated scanning flagged a third-party module with known vulnerabilities still in use.

the outcome

Results and Impact

The review gave the client a clear, prioritized map of the vulnerabilities inside its new digital platform, its acquired-company modules, and its third-party CMS, each explained with technical impact, business impact, and remediation steps. Delivered inside the client's launch window despite a mid-project scope increase, the findings let the security team fix the highest-impact issues before the platform went live.

  • Over 5,00,000 lines of Java and JavaScript code reviewed across the platform and its acquisitions

  • Third-party CMS brought into scope and reviewed within the original deadline

  • Five categories of exploitable issues identified with business impact and remediation guidance

  • Recommendations delivered on endpoint authentication, role-based authorization, and third-party module hygiene

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment