Do not expose internal database IDs in URLs. Instead, use:
: Using Google as a "passive" scanner to find targets without interacting with them directly.
Use stolen admin credentials to deface the site, inject malware, or steal the whole database.
: For developers, this serves as a cautionary tale about the importance of Prepared Statements