Hi, I'm Daniel Púa (a.k.a. devploit), offensive security researcher from Cádiz, Spain. I lead security at Magnific and spend the rest of my time breaking things for a living: bug bounty, penetration testing and code review across web, mobile and APIs. Everything I publish ends up at devploit.dev.
🧰 Things I build and keep online
- JWTForge: decode, audit and break JWTs entirely in your browser. Six attack generators, zero requests sent.
- pwny.cc: a curated payload repository for security researchers.
- x-utils: twelve copy-paste console tools that pull metrics from X without paying for the API. Read-only, no server, no password.
- nomore403: bypass 403/40X responses. 1.9k+ stars, and the reason many of you are here.
🔎 Research
Assigned CVEs across WordPress plugins and the Node.js ecosystem (adm-zip, decompress, pathe), with public advisories and write-ups on the blog. The up-to-date list, with CVSS scores and references, is at devploit.dev/cves.
🏁 Competitive security
CTF player since 2017 with SFPE, ex ripp3rs. The full record of placements and podiums, solo and team, is at devploit.dev/ctf. Represented Spain in the European Cybersecurity Challenge (ECSC) and mentored the national team the year after. I also organise Hack&Beers Málaga.
Same mindset in all of it: If it parses, it breaks. 🧨
👤 Social / Content:
🐛 Bug Bounty:
🛡️ CTF & Security:





