Authentication and sessions
Login, recovery, MFA, session lifecycle, remember-me behavior, rate controls, and account-state transitions.
Authorized penetration testing
A penetration test goes beyond configuration review by exercising an agreed application scope under written authorization. It is suited to custom plugins, themes, APIs, roles, workflows, WooCommerce features, and business logic where exploitability must be demonstrated safely. Testing follows the OWASP Web Security Testing Guide and is performed by an OSCP- and CompTIA PenTest+-certified tester.
Never send credentials, private keys, backup archives, or confidential source code through this website.
Testing scope
Login, recovery, MFA, session lifecycle, remember-me behavior, rate controls, and account-state transitions.
Horizontal and vertical privilege boundaries across administrators, editors, customers, members, vendors, and custom roles.
Approved custom plugins, themes, AJAX actions, REST endpoints, shortcodes, uploads, and server-side handlers.
Workflow manipulation, price or entitlement changes, state transitions, replay, sequencing, and abuse of intended functionality.
Injection, cross-site scripting, request forgery, upload handling, sensitive data exposure, and unsafe error behavior.
Defined third-party callbacks, webhooks, API authentication, data boundaries, and failure handling.
Methodology
Buyers compare penetration tests on method as much as on findings. This is the method.
Test cases are drawn from the OWASP Web Security Testing Guide (WSTG) and organized around the OWASP Top 10, then extended with WordPress-specific classes: capability and nonce checks on AJAX and REST handlers, role boundaries across custom roles, WooCommerce order and coupon logic, upload handling, and the interaction between plugins that were never designed to run together. Each confirmed finding is scored with CVSS v3.1, mapped to the relevant CWE, and written so a developer can reproduce it from the report alone.
Testing is performed personally by G. Schad, who holds the Offensive Security Certified Professional (OSCP), CompTIA PenTest+, and CompTIA CASP+ certifications. Tooling supports coverage; every reported issue is manually validated, and scanner output is never presented as a confirmed vulnerability.
Typical use cases
Checkout, coupon, cart, refund, subscription, and account flows tested for price manipulation, entitlement bypass, and order-data exposure — the store-specific counterpart of the WooCommerce audit.
Security review of code you commissioned or built: AJAX and REST handlers, shortcodes, uploads, options screens, and integrations, with access-assisted source review where it shortens the path to a finding.
Role and content-entitlement boundaries across members, instructors, and administrators, plus the payment and enrolment logic that sits on top of WordPress.
A dated, scoped test with reproducible evidence and a retest record that answers a third party’s security question without a compliance certificate being implied.
Rules of engagement
Audit or penetration test
| Engagement | Primary question | Typical emphasis |
|---|---|---|
| Security audit | Are WordPress and its operating controls configured safely? | Broad coverage of configuration, extensions, accounts, exposure, and recovery. |
| Penetration test | Can an attacker exploit the defined application behavior? | Depth on custom functionality, roles, workflows, APIs, and demonstrated attack paths. |
Reporting
Each confirmed finding identifies the affected functionality, preconditions, sanitized reproduction evidence, realistic impact, and a remediation direction. Findings are discussed before finalization when context may change severity or ownership.
After agreed fixes are available, the affected behavior is retested and the status is recorded. A retest verifies the specific remediation; it is not presented as a new full penetration test unless separately scoped.
Common questions
Yes, when production testing is appropriate and explicitly authorized. Rate, timing, accounts, prohibited actions, monitoring, and escalation procedures are agreed first.
Installed components can be assessed in the context of the site. Broad research against third-party products or infrastructure not owned by the client requires separate authorization and scope.
Not automatically. Targeted access-assisted review can be included when source is available and the objective warrants it.
The report documents the agreed work and observed results. It does not by itself certify compliance with a framework unless that mapping is explicitly included in scope.
Typically $450–$1,500 according to scope, over 5–10 business days. The range follows the breadth of in-scope functionality, roles, APIs, production constraints, and reporting depth; the written proposal fixes the fee for the agreed scope. For comparison, a general web application penetration test from a firm usually starts several times higher — the focus on WordPress and WooCommerce is what keeps this range realistic.
The OWASP Web Security Testing Guide and OWASP Top 10 provide the test cases; findings are scored with CVSS v3.1 and mapped to CWE identifiers. Rules of engagement follow the written-authorization, scope, and evidence-handling practice described on this page. The tester holds OSCP, PenTest+, and CASP+.
Yes. WooCommerce checkout, coupon, and account logic, and custom plugins or themes with their AJAX and REST handlers, are the most common scopes. Test orders, test accounts, and rate limits are agreed so live customers are never affected.