I review AI-built codebases and ship the fixes
Full stack developer specialising in application security.
Auth gaps, exposed secrets, broken access control.
Ask this site
Answers come only from published work on this site, with sources.
Drawn from entries published here
ASK runs in the browser and needs JavaScript. It reads nothing that is not already on this site: the archive below is the corpus, page by page, and it works without scripts.
Start here
Vulnerability writeups
Broken access control, IDOR and secrets shown in real production code, with the fix.
Browse writeupsFree security scan
Paste a public repository and see what an automated web application security pass finds.
Open scanLatest application security work
- WRITEUPSix places a secret survives .gitignoreIgnoring .env stops one file being committed. It does not stop the value reaching the client bundle, the test fixtures, or the history you already pushed.
- WRITEUPIDOR in a Next.js route handler, and why middleware does not stop itRoute handlers are just functions. Middleware authenticates the request, then the handler fetches by id and never checks who is asking.
- RESEARCHWhy AI-generated code fails at authorisation more than at anything elseAssistants are trained to produce code that runs. Authorisation is the one property that cannot be inferred from the surrounding code, because it lives in business rules the model was never shown.


















