Disclosure

This page is for two people: a maintainer who has been told about a defect in their plugin, and anyone who wants to report one to us.

If we reported something in your software

You will normally hear from a CNA — a body authorised to assign CVE identifiers — rather than from us directly. That is deliberate: they have an established channel to maintainers, they run the coordination, and the resulting record outlives any one researcher's website.

What you can expect:

If you would prefer to talk to us directly rather than through the coordinating body, the address below reaches us.

If you want to report something to us

We are a research project, not a vendor, and we do not run a bounty programme — but the site itself is in scope and we would genuinely like to know.

security@mutantgun.com

This site is deliberately unusual as a target: it is static, it ships no JavaScript at all, it sets no cookies, and it makes no third-party requests. The privacy page sets out exactly what that means and why. If you find something that contradicts any of that, it is a real finding and we want it — a claim like "we ship no client code" is only worth anything if someone checks.

Please do not test against anything other than this site.

What we will not do with a report

Not sell it, not sit on it, not use it, and not pass it to anyone other than the coordinating body and the affected vendor.