tool
webscan.dev
A non-intrusive scanner that turns public posture signals such as TLS, headers, and exposed files into readable next steps.
DEVAesia
I review web applications and APIs, build internal tools, and add focused checks to CI/CD. Findings are validated, remediation is clear, and the work fits the release process already in place.
01 / Work
Current tools and publishing projects, with concise notes on what each one does.
tool
A non-intrusive scanner that turns public posture signals such as TLS, headers, and exposed files into readable next steps.
tool
End-to-end encrypted text sharing where the browser holds the key and the server only ever stores a ciphertext envelope.
writing
Developer-focused cybersecurity analysis and practical guidance.
02 / Engagements
Start with a clear scope and leave with a usable handoff.
Web software and internal tools with readable code, safe defaults, and maintainable security controls.
Targeted penetration tests and reviews for web applications, APIs, architecture, and delivery pipelines. Findings include validated issues and clear remediation.
Focused CI/CD checks for dependencies, configuration, baseline scanning, and regressions. Each failure should make the next action clear.
03 / Method
The work stays bounded, testable, and ready for the next person.
Name the system, the allowed boundaries, the risks, and the result this work needs to produce.
Build the software or test the exposed paths. Stay inside the agreed scope.
Reproduce each finding. Test each change. Check the released artifact when deployment is in scope.
Leave the code, findings, and next actions in a form the team can keep using.
04 / Writing
Build-time snapshots from the cybersecurity archive at alexmacra.com.
Romania’s National Agency for Cadastre and Real Estate Registration (ANCPI) has been effectively offline for over two weeks....
Read on alexmacra.com : Leaked credentials brought Romania’s housing market to a complete halt (external site)As with any recent domain, I’ve heard the term “AI pentesting” more often than one would want to....
Read on alexmacra.com : AI Automated Pentesting: The Good, The Bad, The Ugly (external site)The supply chain attack that spread uncontrollably, Shai-Hulud, has gotten out of the news headlines. Now, after the...
Read on alexmacra.com : Shai-Hulud Worm Investigation (external site)05 / FAQ
The short version of how assessments, automation, and development work.
Vulnerability assessments, targeted penetration tests, secure architecture reviews, API testing, and pragmatic hardening guidance. The focus is on validated issues with clear remediation.
I integrate focused checks into CI/CD and developer workflows, including dependency signals, configuration checks, baseline scanning, and guardrails that reduce regressions.
webscan.dev provides quick, non-intrusive posture signals around areas such as TLS, headers, and public files. Deeper testing pairs those signals with a scoped manual assessment.
Yes. I can build custom checks, internal tools, and automation around a specific stack, particularly when an off-the-shelf product does not fit the delivery workflow.
Yes. The aim is to work with the tools and release process already in place so that security findings remain understandable, actionable, and maintainable.
06 / Get in touch
Tell me what you are building, what is uncertain, and what a useful outcome would look like.