1. Scope
In-scope: malwipe.com, api.malwipe.com, and the Malwipe WordPress plugin (all versions). Out of scope: third-party integrations (LemonSqueezy, WordPress.org).
2. Report a vulnerability
Email [email protected] with a proof-of-concept. PGP key available at malwipe.com/.well-known/security-pgp. We acknowledge within 24 hours, patch within 7-30 days depending on severity, and coordinate public disclosure with you.
3. Rewards
We pay bounties for verified issues:
- Critical (RCE, auth bypass): $500 – $2,500
- High (privilege escalation, SSRF): $200 – $500
- Medium (stored XSS, IDOR): $50 – $200
- Low (self-XSS, missing headers): swag + hall of fame
4. Hall of fame
Coming soon — researchers who help us keep Malwipe safe.