How to secure a WordPress site in 2025 : Complete guide
on 03/24/2025 in
WordPress powers more than 43% of the world's websites today, making it the most widely used content management platform (CMS). But this popularity also makes WordPress a prime target for cyber attacks.
Vulnerabilities in extensions, outdated themes, weak configurations... A poorly protected WordPress can easily become an attacker's entry point. Fortunately, there are some simple and effective best practices to reduce the risks.
In this article, we'll take a look at how to secure a WordPress site, with practical advice you can apply today.
FFuF: The essential tool for web pentests
on 03/05/2025 in
When performing a security audit on a web application, it is essential to identify publicly exposed resources, such as files, folders or API endpoints. Enumerating these elements can uncover potential security flaws and expand the attack surface.
There are several tools available for this task, including FFuF (Fast Fuzzing), which we'll discuss here.
The different approaches to Web pentesting
By the Ethical Hacking category
on 03/04/2025 in
Penetration testing, or pentesting, is an essential step in assessing the security of web applications. It involves simulating attacks in order to identify and correct potential vulnerabilities. Different approaches to pentesting exist, each offering a unique perspective on system security. The main methods are blackbox, greybox and whitebox testing.
Learn Web Hacking: The Best Resources
By the Ethical Hacking category
on 02/19/2025 in
If you love cybersecurity and want to start web pentesting, you're in the right spot.
I'm excited to share a list of resources and platforms that helped me start and continue in my career.
You'll find guides, training platforms, and GitHub repositories here.
WPScan: WordPress Vulnerability Scanner
on 06/07/2024 in
WPScan is an open-source tool that allows you to scan a WordPress site to find vulnerabilities and security issues. In this article, I will explain how to install and use WPScan to secure your WordPress sites.
- Pentest vs Bug Bounty: what are the differences and what's in it for you?
- Exploit SQL Injections with SQLMap : Complete Guide
- How often should I run a penetration test on my website?
- 5 cybersecurity mistakes that small businesses still make too often
- Understanding and protecting against XSS (Cross-Site Scripting) vulnerabilities

Do you have questions about your system's security, need a pentest, or want to train your teams in best practices?