Blog

Thoughts on development, design, and everything in between.

9/26/2026

A Paid API Key Sat In The Page, And It Worked

A law firm site with a review widget that rendered a billable geocoding key into the HTML. The finding is narrow, trivially automatable, and the most profitable line item in the report.

9/19/2026

Your Online Shop Exposes A Public API You Did Not Write

A lifestyle and commerce site on a current content platform with a store attached. Seventeen findings, and the store interface was the one nobody audited because it looked like a feature.

9/12/2026

A Nonce In The Page Is Not A Secret, And The Plugin Knew It

A business innovation network ran a patched content platform with fourteen findings. The interesting one was a feature left switched on that published its own request tokens in the page source.

9/5/2026

Modern Front End, Ancient Back Office: Auditing A Hybrid Estate

A petition platform ran a modern framework on the main domain and a legacy content system behind a raw server with no firewall. The modern side was excellent. The legacy side defined the risk.

8/29/2026

What A Ransomware Incident Teaches About The Week Before It Started

A public-sector network was exfiltrated for roughly a week before anyone noticed. This write-up is about the controls that would have shortened that dwell time, not about the attacker.

8/22/2026

The API Documentation Was Public, And It Was The Best Map You Can Ask For

An application built with an automated framework served interactive documentation and a machine-readable schema at a well-known path. Both were enabled by default and neither was behind a login.

8/15/2026

If TLS Enforcement Is Optional, Version Downgrades Become Boring

A university content platform served mixed protocol versions on some hosts. No cipher was weak, no certificate was expired, and the transport layer still failed the assessment.

8/8/2026

A Patched Estate With Six Findings And No Exploits: Reporting Discipline

A restaurant site behind a web application firewall. Every plugin was current, every known exploit failed, and the report still had six findings worth acting on.

8/1/2026

One Finding, Maximum Impact: A Permissive Cross-Origin Policy

A civic content platform on a modern stack produced a single finding of the highest severity. It needed no version check and no exploit; the browser already did the work.

7/25/2026

A Platform For Internal Communication, Exposed To The Internet

A public-facing cooperation and counselling platform ran a content system with three low-severity findings. The lesson was in what a low-severity result does not tell you.

7/18/2026

Error Tracking Telemetry Describes Your Architecture To Anyone With A Browser

A platform provider running a Java backend behind two reverse proxies with a modern front end. The interesting finding was not a vulnerability but an inventory: error tracking revealed the internal structure.

7/11/2026

The Legacy Instance Beside The Modern One Is The Real Estate

One organisation ran two generations of a content platform simultaneously. The modern one was current; the legacy one defined the risk, including a client library past end of life.

7/4/2026

Static Site, Serverless Functions, Twelve Findings

A site builder platform with a content delivery network in front and functions behind it. The static layer was clean; the function layer and the mail configuration were not.

6/27/2026

A Plugin Can Be Current And Still Hand Out Records To Anyone

A fully patched content management system carried a plugin with current releases and twelve findings. The pattern was authorisation: routes that answered before the permission callback ran.

6/20/2026

Error Pages Are An Unintentional API Documentation Endpoint

Across a mixed estate the same three leaks appeared again and again: stack traces, framework banners and absolute filesystem paths. Each one maps the internals for free.

6/13/2026

The Booking Plugin Is The Product, And The Product Is An Admin Surface

A training provider with a booking plugin exposed to the internet exposed its entire administrative surface with it: exports, attendee records, file uploads and an unauthenticated cron.

6/6/2026

A Row Level Security Policy Is A Boundary You Have To Test From The Client Side

A platform-generated application stored every tenant table behind row level security. The policy was correct on paper and bypassable in practice, because the client held a key the policy trusted too much.

5/30/2026

Twenty Findings, One Platform: How Volume Changes The Remediation Order

An industrial supplier with a large content surface produced twenty findings across seven categories. The value was in the ordering, not the count.

5/23/2026

A Single Page Application Hands You Its Own Route Map

A modern framework application with almost no server-side exposure still revealed its administrative surface, because the route table is compiled into the client bundle.

5/16/2026

Eight Attack Vectors, Zero Findings: What A Hardened Single Page Application Looks Like

A negative assessment is a result. This one documents why eight standard vectors failed against a statically served application behind an edge platform.

5/9/2026

WordPress User Enumeration Is Not The Finding, It Is The Multiplier

A tax advisory firm exposed every account slug through its public REST API, shipped no security headers at all, and left the login form without rate limiting.

5/2/2026

A Legacy Municipal CMS With Perfect Transport Security And No Clickjacking Protection

HSTS was immaculate on a German municipal court portal. One missing header still allowed framing, and the CSP permitted script injection outright.