Banned Index

Security policy

Last updated 2026-04-20 · security.txt

Banned Index takes security seriously. If you’ve found a vulnerability — a way to access data you shouldn’t, modify records you shouldn’t, crash the site, or abuse our forms — we want to hear about it, and we’ll treat you well.

Reporting

Email security@bannedindex.org with:

Encrypted email is welcome but not required.

Please do NOT:

Do feel free to:

Our commitment

Scope

In scope:

Out of scope:

Priority

High (immediate): authentication bypass, data exfiltration beyond public data, arbitrary code execution, destructive writes by unauthorized users, widespread PII leak.

Medium (within a week): limited data exposure, stored XSS, server-side request forgery, rate-limit bypass enabling spam/abuse.

Low (when convenient): missing security headers, CSRF on non-sensitive actions, self-XSS, verbose error messages.

Acknowledgments

None yet. You could be first.