Back to @PentesterLab's profile

PentesterLab engagement report

@PentesterLab - 209K followers on X

Measured over 14 original posts from a 30-day window, last computed on October 6, 2026.

Engagement

Bottom quarter for its size
Per follower
0.013%
of 209K followers
Per impression
0.4%
6.8K views on a typical post
Reach
3.24%
of its followers see a post
Typical post
27
interactions (median)
Saved
0.215%
14 bookmarks on a typical post
Posting rate
0.77/day
active 60% of days
Peak time
22:00 UTC
Monday

A typical post picks up 27 interactions against 209K followers, an engagement rate of 0.013%. Measured over 14 original posts, its engagement rate beats 25% of 15,519 tracked accounts of a similar size. That is a reason to look at how the audience behaves - reply depth, saves, whether the followers are recent - rather than a conclusion about it on its own. Posts are seen about 6.8K times each, and 0.4% of those impressions turn into an interaction. That is about 3.23% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 0.77 post a day over the last 30 days, with activity on roughly 60% of days. Most posts go out around 22:00 UTC, and Monday is the busiest day of the week. Of the 14 posts sampled, 21% carry an image or video, 7% are part of a thread and 64% link out. The account's strongest tracked post pulled 202 interactions, about 7.5x its own typical post.

Measured over 14 original posts from a 30-day window, last computed on October 6, 2026.

Compared with accounts its own size

PentesterLab's engagement rate beats 25% of the tracked X accounts closest to it in follower count (15,519 accounts, accounts of similar size (decile 8 of 10)). A percentile is spread evenly by construction, so 50 really is the middle of that group and 90 really is its top tenth.

On engagement per impression rather than per follower it beats 22% of the same group. When those two numbers disagree, the gap is about how far its posts travel rather than how people react to them.

Where this sits in the catalog

At 0.013%, PentesterLab sits above the 10th percentile of the 156,839 accounts in this comparison. That places it in the bottom 25% band, which runs below 0.022%.

p100.003%
p250.022%
p50 (median)0.128%
p750.604%
p902.32%
p9983.4%
Engagement rate as a share of followers, across the 156,839 accounts we have scanned enough to measure. The axis is logarithmic, because the top and bottom of this population are about 26,058 times apart and a linear axis would flatten everything below the median into a single point.
Show the percentile table
Engagement rate percentiles
PercentileEngagement rate
10th percentile0.003%
25th percentile0.022%
50th percentile0.128%
75th percentile0.604%
90th percentile2.32%
99th percentile83.4%

This ruler is the whole measured catalog, not a size-matched group: it shows where the raw rate falls across every account we can measure, all of which are large. For a like-for-like comparison, read the size-band percentile above instead. See how the bands are built

Posting timing

This account posts most often around 22:00 UTC, and Monday is its busiest day of the week. The bars below are the catalog-wide pattern, with this account's own busiest slot marked. They do not show how this account performs at each hour: we keep one aggregate per account, not one per hour, so that measurement does not exist in our data.

Engagement by hour posted, UTCTwenty-four bars, one per UTC hour. Each bar shows how posts published in that hour compare with their own authors' median engagement. Bars above the centre line ran higher than the median, bars below ran lower. A marker flags Busiest hour: 22:00 UTC.
0003060912151821
Above the authors' own mediansBelowScale: plus or minus 111%Busiest hour: 22:00 UTC
Show engagement by hour posted, utc as a table
Engagement by hour posted, UTC
Hour (UTC)Vs author medianPosts
00:00 UTC-1%89K
01:00 UTC-2%90K
02:00 UTC-3%88K
03:00 UTC-4%94K
04:00 UTC-5%76K
05:00 UTC-4%75K
06:00 UTC-5%86K
07:00 UTC-5%93K
08:00 UTC-4%108K
09:00 UTC-4%124K
10:00 UTC-3%129K
11:00 UTC-3%141K
12:00 UTC-3%154K
13:00 UTC-3%167K
14:00 UTC-4%173K
15:00 UTC-2%176K
16:00 UTC-3%171K
17:00 UTC-3%159K
18:00 UTC-2%149K
19:00 UTC-2%141K
20:00 UTC-1%131K
21:00 UTC0%116K
22:00 UTC-2%100K
23:00 UTC-1%90K
Engagement by day of weekSeven bars, one per weekday, Sunday first. Each bar shows how posts published on that day compare with their own authors' median engagement. Bars above the centre line ran higher than the median, bars below ran lower. A marker flags Busiest day: Monday.
SunMonTueWedThuFriSat
Above the authors' own mediansBelowScale: plus or minus 111%Busiest day: Monday
Show engagement by day of week as a table
Engagement by day of week
DayVs author medianPosts
Sunday+5%393K
Monday+1%483K
Tuesday-2%520K
Wednesday-3%472K
Thursday-2%430K
Friday-3%447K
Saturday+2%393K
See what moves engagement across the whole catalogWhat counts as a good engagement rate at this size

Formats this account uses

Its own posting mix on the left, and what each of those formats does across every account we track on the right. Only formats where the effect clears our publish test appear here, so an empty row is a format we could not measure rather than one that does nothing.

This account's posting mix compared with catalog-wide effects
FormatThis accountCatalog effect95% intervalAccounts behind it
Image or video21% of posts+111%+108% to +115%34K
Outbound link64% of posts-41%-42% to -40%32K
Typical length-no effect-2% to -1%42K
  • 21% of this account's sampled posts carry an image or video. Across the catalog, posts with an image or video run 111% above the same accounts' other posts.
  • 64% of its posts carry a link off X. Across the catalog, posts with an outbound link run 41% below the same accounts' other posts, so a large share of this account's output sits in the weakest bucket we measure.
  • Its average post runs 269 characters, which falls in the 180 - 280 characters band. Across the catalog, posts of 180 to 280 characters match the same accounts' other posts almost exactly.

These are catalog-wide differences applied to this account's own posting mix, not a measurement of how each format performs for this account specifically. We keep one median per account, not one per format per account, so the second thing is not something this data can tell you.

Best tweets

  • Sep 14, 20267.5x their median

    https://t.co/ycqf4AbUuy

    18019127.0K viewsView on X
  • Jun 30, 20254.2x their median

    💥🐹 4 new Go Code Review Labs just dropped! 🐹💥 Read the code, peek at the diff, find the bug. Sharpen your skills: https://t.co/0Y56bXk2oa

    97125035K viewsView on X
  • Aug 12, 20262.6x their median

    A valid SAML signature does not always mean the identity is trustworthy. Our new practical guide covers signature stripping, XML Signature Wrapping, XSLT RCE, SAMLStorm and parser differentials and we have hands-on labs for each: https://t.co/u3FJFKJJat

    5217016.8K viewsView on X
  • Jul 19, 20262.3x their median

    The exploit has now been public on GitHub for several hours, and WordPress has a built-in automatic update mechanism, so we have released our #wp2shell lab. It includes a safe environment to reproduce the issue, more details on the vulnerability and exploit, and indicators of compromise for defenders.

    518407.1K viewsView on X
  • Jun 28, 20262.3x their median

    When you find a pickle.loads() in a pull request... https://t.co/XbicaXZCWN

    555205.6K viewsView on X
  • Aug 9, 20262.1x their median

    Every pentester knows the feeling... https://t.co/8W0YthYj6Y

    525017.1K viewsView on X
  • Sep 17, 20262.0x their median

    One of the biggest mistakes beginners make when testing an application is not reading the error messages properly. They send a payload, get an error and conclude that it did not work. Then they send another payload, get another error and assume it is basically the same thing. But an error does not mean the payload did not work. It just means that an error was triggered somewhere in the execution path, and that point may be after the interesting part already happened. Your payload may have been parsed successfully, changed the control flow, bypassed a check, reached a different function or triggered behaviour that the previous payload did not. Something later may simply have failed. This is why small differences matter so much. A different exception, a slightly different message, a different status code or even a different location in a stack trace can tell you that you moved forward. Security testing is often about noticing those tiny changes and asking why they happened. Don’t just look for success or failure. Read the error.

    437127.8K viewsView on X
  • Aug 26, 20261.6x their median

    Never Quit! https://t.co/4RTITs1DAt

    403017.0K viewsView on X
  • Aug 14, 2026

    Most code review training is offensive code review: "Find a sink. Trace it to a source. Prove exploitability." In this webinar, @snyff will cover the Exploitability Tax and why code review should focus on hardening the codebase, not just finding the next bug. https://t.co/LwxJH3xdF2

    354106.7K viewsView on X
  • Sep 7, 2026

    We are going to run another "bug club" next week: https://t.co/9QyJAP9u5p This will include a hands-on component!

    345006.7K viewsView on X

Ranked by total interactions across everything we have tracked for this account, which is a longer history than the 30-day window the rates above use. The multiple compares each post to this account's own median.

Buy or sell Twitter (X) accounts - escrow-protected

PlayerSells is an escrow marketplace for Twitter (X) accounts. Every deal is protected, with no middleman risk.

Reading these numbers

A typical post picks up 27 interactions against 209K followers, an engagement rate of 0.013%. Measured over 14 original posts, its engagement rate beats 25% of 15,519 tracked accounts of a similar size. That is a reason to look at how the audience behaves - reply depth, saves, whether the followers are recent - rather than a conclusion about it on its own. Posts are seen about 6.8K times each, and 0.4% of those impressions turn into an interaction. That is about 3.23% of the follower count, which is the gap between an audience on paper and an audience in a timeline. Posting runs at about 0.77 post a day over the last 30 days, with activity on roughly 60% of days. Most posts go out around 22:00 UTC, and Monday is the busiest day of the week. Of the 14 posts sampled, 21% carry an image or video, 7% are part of a thread and 64% link out. The account's strongest tracked post pulled 202 interactions, about 7.5x its own typical post.

What is PentesterLab's engagement rate on X?
PentesterLab (@PentesterLab) has an engagement rate of 0.013%, based on the median interactions across 14 original posts from the last 30 days against 208,777 followers. Replies, reposts and quote-posts of other people are excluded from that sample.
Is that a good engagement rate?
At 0.013%, PentesterLab sits above the 10th percentile of the 156,839 accounts in this comparison. Those comparison accounts are all large ones, because our scanning cadence is weighted towards big accounts, so this is a ranking among peers of similar scale rather than a ranking across X.
Does @PentesterLab have real engagement?
Its engagement rate beats 25% of the tracked X accounts closest to it in follower count (15,519 accounts), which puts it in the bottom quarter for its size group. Ranking inside a size band matters because engagement rate falls as accounts grow, so a raw rate would mostly re-measure the follower count. It is a starting point for a look at follower quality, not a verdict on it.
When does @PentesterLab post?
Most posts go out around 22:00 UTC, and Monday is its busiest day, at roughly 0.77 posts per day across the measured window.

Keep going