Skip to main content
JoeDostie.com

Security policy

If you think you have found a security problem with this site, I would rather hear about it than not. This page explains how to tell me and what happens next.

How to report

Email [email protected]. Include a clear description of the issue, the steps to reproduce it, and any screenshots or proof-of-concept code that helps me confirm it. Plain text is fine — there is no form to fill in and no bug bounty platform in the way.

What to report

  • Authentication or authorization flaws
  • Cross-site scripting (XSS) or injection vulnerabilities
  • Sensitive data exposure
  • Anything that could allow unauthorized access to data or site functionality

Out of scope

  • Denial of service attacks
  • Spam or social engineering
  • Publicly disclosed issues in third-party plugins or themes
  • Automated scanner output with no proof of exploitability

What you can expect

  • An acknowledgement that your report arrived
  • Updates as I investigate and fix the issue
  • Credit for the discovery, if you want it

Safe harbor

I will not pursue legal action against researchers who find and report vulnerabilities in good faith, provided they do not access, modify or delete data belonging to anyone else, and do not disrupt normal operation of the site.

Spam protection

Forms on this site are protected by Cloudflare Turnstile. When you submit a form, your interaction may be processed by Cloudflare under their Privacy Policy and Terms of Service.

A machine-readable version of this policy is published at /.well-known/security.txt.