Responsible disclosure
Published 2026.08.03
If you believe you have found a security vulnerability in this website or the WGO project, thank you for reporting it responsibly. We would rather hear it from you than read about it later.
This page is the human-readable policy behind our
security.txt file.
Scope
In scope:
wgo-audit.com,brand.wgo-audit.com, and the Cloudflare Worker that serves them;- the contact form and how it handles what you submit;
- published machine-readable files such as
security.txtandrobots.txt; and - the open-source code at
wgo-audit/code.
Out of scope:
- the third-party services listed on our Sub-processors page — report those to the provider, though a note to us is appreciated;
- denial-of-service or load testing of any kind;
- social engineering of the maintainer, contributors, or users;
- spam, phishing, or credential-stuffing; and
- findings that only affect outdated or unsupported browsers.
Rules of engagement
Please:
- report promptly, with enough detail to reproduce the issue;
- use only your own data and your own test submissions;
- avoid accessing, changing, or deleting data that is not yours;
- avoid persistence, lateral movement, and destructive testing; and
- give us a reasonable chance to respond before disclosing publicly.
The contact form is rate-limited. Please describe an issue rather than working around that limit to demonstrate it.
How to report
Report privately through
GitHub Security Advisories,
or use the contact address in
/.well-known/security.txt. Include the affected
URL or component, the vulnerability type, steps to reproduce, the impact you
believe it has, and how you would like to be credited, if at all.
What to expect
WGO is a small open-source project, not a staffed bug-bounty programme. We aim to acknowledge good-faith reports within five business days and to keep you informed while we investigate; timelines depend on severity. There is no monetary bounty, but we are glad to credit you publicly where a report leads to a fix, if you want that.
Safe harbour
We will not pursue or support legal action against good-faith security research that follows this policy, respects privacy, avoids harm to people and data, and does not degrade the service. If you are unsure whether something is in scope, ask first — a question costs nothing. This safe harbour covers systems we operate; it cannot authorise testing against the third-party services we depend on.