Skip to content

AI penetration testing

We will hack you.Or you don’t pay.

AI that attacks your application the way an intruder would — chaining two small weaknesses into one real breach — then hands you the code that did it.

The first scan is free. You only pay if we find something.

Nothing runs until you signNothing to install

A real finding as it appears in a report

Exploited — we ran it

An unauthenticated attacker could sign in as an admin

9.8
Critical
Where
WooCommerce OTP plugin
Type
CWE-640
Scored by Wordfence, not by us
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

We built a disposable WordPress instance, installed the plugin, and reproduced the bypass against it.

CVE-2026-77264Wordfence advisory ↗No patch as of 13 September 2026

Coverage

How much of it gets looked at.

If most of the work was mechanical, a machine should do it — on every change, without a fortnight’s luck deciding what gets found.

A fortnight

Two people, against millions of lines. Their own report says so, in the scope paragraph at the back.

A machine

The same surface again on the next change, and the one after that. Nothing here gets bored at hour nine.

Our first CVE scored 9.8.

The password you never needed

Published by Wordfence, credited to RIA Labs. The score is theirs, not ours.

2 more are published, scored by WPScan.

What you get

Every finding arrives with its evidence

01Where it isFree scan

The exact endpoint or function, with a CWE class and a CVSS score computed by a library.

02Proof it worksPaid report

On a web target, the exploit as a script. Fire it again after the fix and watch it fail.

03How to fix itPaid report

With your source, a diff against the lines responsible, ready for a pull request.

Each CVSS 3.1 metric is submitted one at a time and validated, and a library derives the score from them — because a model asked to name a severity will say “high” and mean nothing by it.

What we test

Whatever you actually ship

Web apps and APIs

The running application, from outside or with your source.

Source repositories

Where a guess becomes a finding.

Compiled binaries

Almost nobody tests this

The endpoint software you ship. Static: pinned to the function, never run.

AI agents and LLM apps

Whether what it reads can make it call a tool or leak data.

Forty-plus classes of bug, mapped to CWE, including the OWASP API Security Top 10.

What you receive

It ends in a document you can read.

Finding in full · published record

High

External Control of File Name or Path in a front-end form builder plugin

Class
CWE-73 · External Control of File Name or Path
Score
7.4 · High
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Component
Frontend Admin by DynamiApps
Affected
< 3.29.13
Published
2 September 2026 by WPScan, credited to RIA Labs
Precondition
Requires a non-default form configuration.
Status
Patched — verified 2 September 2026
Exploited — we ran it

A paid report carries a proposed fix with every finding. On a web target it carries the script that reproduced it, so you can fire it again after the fix and watch it fail.

Before we touch anything

Some of it is already public.

A breach usually starts with someone reading. Our OSINT scan reads the same public records first. Real findings, anonymised:

Nothing was touched

Brand lookalike domains, weeks from lapsing

No transfer lock. Either they are about to be lost, or somebody else has held them all along.

Public domain registry records

A naming convention that published the way around the shield

Every protected host named its own unprotected origin. Sixteen pairs of sixteen, confirmed.

Public certificate records and DNS

219 internal addresses, published

92 DNS records, each labelled with the environment it belongs to.

Public DNS

Every estate had real things right, and the report says which. Every “nothing found” is proven with a control, not a shrug.

And what other people published under our name

Findings by RIA Labs published and scored by a third party
IdentifierScoreClassSubjectGradePublisherFix
CVE-2026-772649.8CriticalCWE-640WooCommerce OTP pluginexploitedWordfencenone as of 13 September 2026
CVE-2026-813477.4HighCWE-73front-end form builder pluginRequires a non-default form configuration.exploitedWPScanpatched
CVE-2026-849365.3MediumCWE-284media embedding pluginexploitedWPScanpatched

Scored by the publisher, not by us. More on the way.

In their words

I've used RIA Labs OSINT module. The report is very good. Detailed, actionable, love it!
Marius MihalecFounder, GenticFlowProfile ↗
The report was thorough, well organized, and the quality and relevance of the findings stood out to meRead the rest, particularly in the way they translated detailed technical observations into clear, actionable priorities. I appreciated the disciplined approach to the assessment and the practical, executive-friendly way the results were presented. Show less

On our external surface review

Brian ArnoldGeneral Counsel, Lakeside SoftwareProfile ↗

RIA Labs' founder is CTO of Lakeside Software, and this review examined his employer's own estate.

The first scan is free.

Pay only if we find something.

Get a free scan