Blog
Thoughts on development, design, and everything in between.
Your Online Shop Exposes A Public API You Did Not Write
A lifestyle and commerce site on a current content platform with a store attached. Seventeen findings, and the store interface was the one nobody audited because it looked like a feature.
A Nonce In The Page Is Not A Secret, And The Plugin Knew It
A business innovation network ran a patched content platform with fourteen findings. The interesting one was a feature left switched on that published its own request tokens in the page source.
Modern Front End, Ancient Back Office: Auditing A Hybrid Estate
A petition platform ran a modern framework on the main domain and a legacy content system behind a raw server with no firewall. The modern side was excellent. The legacy side defined the risk.
A Patched Estate With Six Findings And No Exploits: Reporting Discipline
A restaurant site behind a web application firewall. Every plugin was current, every known exploit failed, and the report still had six findings worth acting on.
A Plugin Can Be Current And Still Hand Out Records To Anyone
A fully patched content management system carried a plugin with current releases and twelve findings. The pattern was authorisation: routes that answered before the permission callback ran.
The Booking Plugin Is The Product, And The Product Is An Admin Surface
A training provider with a booking plugin exposed to the internet exposed its entire administrative surface with it: exports, attendee records, file uploads and an unauthenticated cron.
Twenty Findings, One Platform: How Volume Changes The Remediation Order
An industrial supplier with a large content surface produced twenty findings across seven categories. The value was in the ordering, not the count.
WordPress User Enumeration Is Not The Finding, It Is The Multiplier
A tax advisory firm exposed every account slug through its public REST API, shipped no security headers at all, and left the login form without rate limiting.