$99 · hours, not weeks · next one free if we find nothing
Go hack yourself.
Before someone else does.
You prove you own it. We try to get in. You get the holes, in English.
Your site only. Nothing to install. You prove ownership first.
You are not too small to get hacked
Attackers do not pick targets in a meeting. They run programs that knock on every login, form, and admin URL they can find. A shop, a booking page, a brochure with a contact form: if it is on the internet, it is on the list. Size is not a shield.
Your login page
Guessable passwords, a forgot-password flow that leaks, a stay-logged-in cookie that never dies. If people sign in, someone will try to sign in as them.
Test this - $99 →
The form you added last year
Contact, quote, search, newsletter. If it emails you or talks to a database, it can be abused. Most sites have at least one of these sitting open.
Test this - $99 →
The admin URL you thought was secret
/admin, /wp-admin, a staging site, an old dashboard. Hiding a page behind a quiet URL is not a lock. Bots try the usual names first.
Test this - $99 →
The software you stopped updating
A plugin, a theme, a checkout widget, a library from 2019. Known holes have known recipes. You do not have to be famous. You have to be unpatched.
Test this - $99 →
This is you hiring someone to break in
People call it a pentest. You do not have to. You give permission. We try to get in the same way a stranger would. Then we write down every hole that actually worked, how bad it is, and how to close it.
You say it is yours
Buy the test and prove you own the website. Nothing runs without that. It is your site, your permission.
We try the door
Automated agents attack the live site the way a real attacker would: find what is exposed, try to get in, prove it.
You get the write-up
A PDF you can read. What they got through, how, how bad, and how to fix it. Plus a letter you can show a customer that the test happened.
This is the document you walk away with
Ranked findings, written in English, with what to do next. If we find nothing, your next test is free.
Penetration Test Report
ginandjuice.shop · 2026-03-29
Executive Summary
An automated black-box pentest identified 18 findings across all severity levels. The most severe include a complete admin panel access-control bypass (CVSS 10.0), plaintext credential disclosure, SQL injection, and blind XXE injection - each with proof-of-concept and remediation steps.
4
Critical
7
High
4
Medium
2
Low
1
Info
Admin Panel Access Control Bypass via X-Original-URL Header
Includes reproduction steps, proof-of-exploit, and remediation.
The rules of hacking yourself
Your site only
Nothing runs until you prove you own the website. We do not test anyone else's property. Ever.
Nothing to install
No plugin, no agent, no code change. You prove ownership. We test from the outside, the way a stranger would.
Not a free checker
A free website checker lists maybes. This tries to actually get in, proves what worked, and writes up how to close it.
Questions people ask before they type a domain
Is this legal?
Yes, because it is your website. You prove ownership before anything runs. Hack yourself means an authorized test of a site you own. Nothing else.
Do I need to know what a pentest is?
No. A pentest is just a permissioned break-in with a write-up. Type a website you own. Read a report written in English. Every finding says what it is, why it matters, and how to fix it.
Will this break my website?
We do not install anything and we do not change your site. We send the kind of traffic a real attacker would: logins, form posts, looking for hidden pages. Most sites never notice. If you run a very small server, start the test at a quiet hour. You prove ownership first, so this is never a surprise.
I already have HTTPS / Cloudflare / a security plugin. Do I still need this?
HTTPS stops people from snooping on the way to your site. A CDN can soak up junk traffic. A plugin can block some obvious attacks. None of them sit down and try to log in as a stranger, abuse your forms, or find an admin page you forgot. That is the gap.
What if you find nothing?
If we find nothing, your next test is free. You can also explore a live demo first, with no card required.
Is $99 really the price?
Yes. $99 per website, flat. No subscription, no credit packs, no annual contract, no minimum. Deeper tiers exist if you want more hours. The door opens at $99.
How is this different from a free 'scan my website' tool?
A free checker looks at the surface and hands you a list of maybes. This tries to actually break in, proves it, and tells you how to close the hole. Checking that the lock is there is not the same as hiring someone to try the door.
Hack yourself first.
You do not need a security team. You need a website you own, and ninety-nine dollars.
Know someone with a website?
Want the longer version?