AI Makers

AI Pen Testing

Find the holes before they do.

I test your site the way a real attacker would, then hand you the report.

See the Scanner
WordPress fingerprint & version detection
User enumeration (REST API, author, login)
XML-RPC brute force testing
Security headers & SSL/TLS audit
Sensitive file exposure (.git, .env, backups)
CVSS-scored report + free retest

Scope depends on what you need tested. Send me the URL — I'll come back with a quote and a timeline.

AI Pentest Scanner
Scanning

Real findings

Real holes, from real assessments.

CRITICAL

Admin password cracked

XML-RPC multicall allows 1,000 password attempts per request. Admin password found in 23 seconds.

CVSS 9.1
CRITICAL

Source code exposed

.git repository publicly accessible. Full source, config files and commit history downloadable.

CVSS 8.6
HIGH

Database credentials leaked

Backup wp-config.php~ contains database host, username and password in plain text.

CVSS 8.2
HIGH

User data enumeration

REST API exposes every username and ID at /wp-json/wp/v2/users — no authentication required.

CVSS 7.5
HIGH

Clickjacking vulnerable

No X-Frame-Options or CSP frame-ancestors. The site can be embedded in a malicious iframe.

CVSS 6.1
MEDIUM

Outdated software

Theme carries 3 known CVEs. WordPress and 4 plugins behind on security patches.

CVSS 5.3

AI Security

Ready to find your blind spots?
Let's test it.

Send me your URL. I'll come back with everything an attacker would find.

Response within 24 hours
No-commitment discovery call
Free project assessment

Send me a message

I'll get back to you within 24 hours.