Web Hack List

Security

Reporting a security issue

How to report a security issue in the Web Hack List website or tooling: use GitHub private security advisories. Open source, no bug bounty, no payment.

Where to report

Report privately through GitHub security advisories on the repository that runs this site:

Open a private security advisory ↗

That form is private between you and the maintainer until an advisory is published. Please use it rather than a public issue for anything exploitable. If you cannot use GitHub at all, open a normal issue that says only that you have a security report and asks for a contact route — do not put the details in it.

Please read this first

In scope

Out of scope

Testing rules

Test only against your own copy where you can — the whole site builds and runs locally from the repository. Against the live site, keep it to what a single browser can do by hand. Do not run scanners or floods against it, and do not attempt to reach anything beyond the public files.

What to expect

This is maintained in spare time, so a first reply may take a couple of weeks. Valid issues are fixed and published as a GitHub advisory with credit to the reporter unless you ask otherwise. Not every report will be treated as a vulnerability, and the reasoning will be explained when it is not.

Other kinds of report

A wrong byline, a bad capture, a dead link or a misattributed technique is not a security issue and is very welcome as a normal GitHub issue. If you are an author who wants a preserved copy of your own work changed or removed, open an issue and say so — that is honoured.