Web Security
Testing web applications and understanding real attack surfaces.
Private bug bounty researcher focused on web security, practical testing, and automation.
I work primarily on private bug bounty engagements, study web application behavior, and build simple workflows that improve the quality and efficiency of my research.
Testing web applications and understanding real attack surfaces.
Focused on private programs, practical attack paths, and high-signal testing.
Building lightweight workflows that make security research more efficient.
I am a full-time private bug bounty researcher with a strong interest in web application security, practical analysis, and continuous learning through hands-on work. I enjoy understanding how systems behave, identifying meaningful security issues, and refining my workflows over time.
Login, reset flows, session handling, identity checks, and account recovery paths.
Permission boundaries, role checks, tenant separation, and IDOR-style issues.
Application workflows, trust assumptions, and practical high-impact logic flaws.
I am available for limited-scope web application security reviews with a focus on practical testing, authentication and access control, and business logic issues.
Engagements are scoped carefully and handled with a practical, manual-testing approach.
Authentication flows, authorization and access control, account management, invitation flows, file access, application logic, and other web application attack surfaces.
Small, clearly scoped engagements with manual testing, practical findings, reproducible reports, and straightforward remediation notes.
Web applications, user flows, account roles, permission boundaries, and business logic reviews.
I contribute practical improvements to open-source projects, with recent merged work spanning accessibility, frontend performance, configuration, and code quality updates.
Cleaned up singularize-related dead code warnings and aligned the change with the project’s feature-gated build requirements after review feedback.
View PR
Added configurable max_body_size support to server configuration and
documented the setting for cleaner request size control.
Improved markdown rendering performance by lazy-loading the syntax highlighter only when fenced code blocks are actually rendered.
View PR
Improved accessibility by adding proper aria-label and
aria-pressed support to the web search toggle for assistive technology.
More public work, experiments, small utilities, and contributions are available on my GitHub profile.
Visit GitHubI prefer small, reviewable changes that improve usability, maintainability, performance, and implementation quality in real codebases.
Available for private security work, research discussions, and security-related inquiries.