console session — user: mentor404

I find the way in,
then help you close it.

Web application penetration tester and full-stack developer. I test production apps for real vulnerabilities, then build the software that fixes the class of bug I just found.

0 Bounty platforms
Bugcrowd & HackerOne
0 Targets tested
from recon to report
0 Security plugin shipped
WP-Shield, AI-assisted

What I actually do

01

Web App Penetration Testing

Manual testing on live bug bounty programs — GraphQL mutation abuse, IDOR/BOLA, JWT and session flaws, CSRF, rate-limit bypasses. Recon-first workflow with Burp Suite, ffuf, subfinder and Wappalyzer before a single request is sent with intent.

02

WordPress & PHP Security

Deep familiarity with how WordPress/PHP stacks fail — SQLi, XSS, brute-force, unrestricted file uploads — from both the attacker and the defender's seat, which is exactly what shaped WP-Shield.

03

Full-Stack & AI-Assisted Delivery

Ship real client sites and chatbots end-to-end — front end, back end, and the AI layer wired on top — for businesses that need working software, not a proof of concept.

Languages I build and break things in

JavaScript

Node backends, chatbot logic, and the DOM-level bugs that show up when a frontend trusts input it shouldn't.

Python

Recon tooling, quick exploit scripts, and automating the parts of a pentest that don't need a human doing them by hand.

PHP

Where WP-Shield lives — and where most of the WordPress vulnerabilities I test for actually originate.

Final Year Project · NUML

WP-Shield

A WordPress security plugin that watches traffic in real time and explains what it sees.

Built to stop the exact bug classes bug-bounty recon keeps turning up on WordPress/PHP targets: SQL injection, XSS, brute-force login attempts, and unauthorized file uploads — caught by a three-layer detection system, not a single pattern list.

  • 17 SQL injection detection patterns
  • 22 XSS detection patterns
  • Honeypot-based brute-force trapping
  • MIME-verified upload filtering
  • GPT-4o powered admin dashboard for plain-language threat analysis
  • Chart.js activity dashboard, tested against a live OpenAI key on a local dev stack

Core functionality complete · exploring CodeCanyon, Lemon Squeezy and SaaS-licensing paths to release it.

From the recon log

A running notebook, not a highlight reel — most testing ends in "not applicable," and that's fine.

shop.monash.edu

Magento target — traced an email-change account-takeover vector, exposed API keys, internal hostnames leaking via CSP headers, and staff PII.

lookfantastic.com

GraphQL UpdatePassword mutation testing through Burp Suite — probing introspection and batching behaviour.

thefork.com

IDOR/BOLA testing across GraphQL mutations and Bugcrowd API responses returning private profile data.

balochdev.com

React Router 7 + Express/Supabase stack — recon focused on git history secrets, Multer upload handling, and Supabase RLS misconfigurations.

MN Secretary of State — VDP

Tested search and API endpoints under Bugcrowd's public VDP program.

Experience

Full-Stack Developer, Freelance

2025

Bezanjo Enterprises — bezanjoenterprisesll.com

Built and deployed the company's corporate website end-to-end — structure, styling, and deployment — as the client-facing front door for the business.

Full-Stack Developer, Freelance

2025

Gulf Enterprise — thegulfenterprise.com

Designed and integrated an AI chatbot into the business's site, handling visitor queries and routing leads without a human at the keyboard.

Final Year Project — WP-Shield

In progress

NUML Islamabad, BSCS

Designing and building a WordPress security plugin with a GPT-4o-powered admin dashboard, from proposal through interim submission.

Currently sharpening

TryHackMe

Working through the Web App Pentester path — closing gaps around race conditions, insecure deserialization, HTTP request smuggling and SSRF.

PortSwigger Web Security Academy

A two-month self-study plan through the authentication, access-control and business-logic-flaw labs, paired directly with TryHackMe rooms.

OSCP → OSWA → OSWE

Mapping a certification path forward from where the bug bounty work currently tops out.

Let's talk

Open to security testing engagements, WordPress security work, and full-stack builds.