Security policy
How to report a security vulnerability in this website.
Last updated 19 September 2026
Reporting a vulnerability
If you believe you have found a security issue in this website, please report it privately through the contact form (choose "Report a security issue") or by email to the contact form. Include steps to reproduce and, if possible, the affected URL. Please do not access other people's data, degrade the service, or publish the issue before we have had a reasonable time to fix it.
What to expect
We acknowledge reports within a few working days, keep you informed of progress, and credit you if you wish once the issue is resolved. We will not take legal action against researchers who act in good faith and within this policy.
Out of scope
Issues in third-party sites we link to, volumetric denial of service, and reports generated solely by automated scanners without a demonstrated impact.
