Disclosure
This page is for two people: a maintainer who has been told about a defect in their plugin, and anyone who wants to report one to us.
If we reported something in your software
You will normally hear from a CNA — a body authorised to assign CVE identifiers — rather than from us directly. That is deliberate: they have an established channel to maintainers, they run the coordination, and the resulting record outlives any one researcher's website.
What you can expect:
- The report is written to be reproduced. Affected versions, the exact request, the conditions the defect needs, and what was actually observed — not a description of what might happen.
- No deadline from us. We do not set a disclosure clock and we do not use one as leverage. The timing belongs to the coordinating body and to you.
- Nothing public until it is settled. We publish only once the CVE is public and the coordinating body confirms disclosure is complete. Until then the finding is not named, hinted at, or described by mechanism, anywhere. And where the coordinating body withholds the proof of concept past publication to give sites time to update, we hold ours back to the same date — an advisory being public does not make the exploit ours to release.
- We read the fix. When a release is published as carrying the fix, we pull it and check that the defect is actually gone, that the new check refuses rather than merely computes, and that nothing was traded for it. If we think a patch is incomplete we will tell you before we tell anyone else.
- Corrections welcome. If part of a report is wrong, say so and it gets fixed. A defect that turns out not to exist is a defect in our work, and we would rather find that out from you than publish it.
If you would prefer to talk to us directly rather than through the coordinating body, the address below reaches us.
If you want to report something to us
We are a research project, not a vendor, and we do not run a bounty programme — but the site itself is in scope and we would genuinely like to know.
This site is deliberately unusual as a target: it is static, it ships no JavaScript at all, it sets no cookies, and it makes no third-party requests. The privacy page sets out exactly what that means and why. If you find something that contradicts any of that, it is a real finding and we want it — a claim like "we ship no client code" is only worth anything if someone checks.
Please do not test against anything other than this site.
What we will not do with a report
Not sell it, not sit on it, not use it, and not pass it to anyone other than the coordinating body and the affected vendor.