Blog

Thoughts on development, design, and everything in between.

9/19/2026

Your Online Shop Exposes A Public API You Did Not Write

A lifestyle and commerce site on a current content platform with a store attached. Seventeen findings, and the store interface was the one nobody audited because it looked like a feature.

9/12/2026

A Nonce In The Page Is Not A Secret, And The Plugin Knew It

A business innovation network ran a patched content platform with fourteen findings. The interesting one was a feature left switched on that published its own request tokens in the page source.

9/5/2026

Modern Front End, Ancient Back Office: Auditing A Hybrid Estate

A petition platform ran a modern framework on the main domain and a legacy content system behind a raw server with no firewall. The modern side was excellent. The legacy side defined the risk.

8/8/2026

A Patched Estate With Six Findings And No Exploits: Reporting Discipline

A restaurant site behind a web application firewall. Every plugin was current, every known exploit failed, and the report still had six findings worth acting on.

6/27/2026

A Plugin Can Be Current And Still Hand Out Records To Anyone

A fully patched content management system carried a plugin with current releases and twelve findings. The pattern was authorisation: routes that answered before the permission callback ran.

6/13/2026

The Booking Plugin Is The Product, And The Product Is An Admin Surface

A training provider with a booking plugin exposed to the internet exposed its entire administrative surface with it: exports, attendee records, file uploads and an unauthenticated cron.

5/30/2026

Twenty Findings, One Platform: How Volume Changes The Remediation Order

An industrial supplier with a large content surface produced twenty findings across seven categories. The value was in the ordering, not the count.

5/9/2026

WordPress User Enumeration Is Not The Finding, It Is The Multiplier

A tax advisory firm exposed every account slug through its public REST API, shipped no security headers at all, and left the login form without rate limiting.