How to Report
Please email hello@cyberxplainer.com with:
- Steps to reproduce the issue (affected URL, parameters, screenshots).
- Impact assessment and any proof of concept.
- Your preferred attribution (name/alias) if you want recognition.
Guidelines
- Don’t access, modify, or exfiltrate data that isn’t yours.
- Don’t run automated scans that could degrade site performance.
- Give us reasonable time to investigate and fix before public disclosure.
Out of Scope (Examples)
- Self‑XSS, clickjacking on static pages without sensitive actions.
- Missing security.txt, lack of SPF/DMARC alignment, best‑practice recommendations.
- Third‑party platform issues (e.g., vendor bugs outside our control).
Acknowledgments
We recognize researchers who responsibly disclose valid issues on our Hall of Fame (unless anonymity is requested).
Scope
This policy applies to cyberxplainer.com and subdomains operated by CyberXplainer.