Security
Reporting a security problem
If you find a vulnerability in crawlcheck.io, its API, the browser extension or the published scanner code, email hello@crawlcheck.io with the subject line Security report. The machine-readable version of this page is security.txt.
What to include
The URL or endpoint, the steps to reproduce it, what an attacker gains, and whether you believe any data belonging to someone else was exposed. A proof of concept that stops at the first sign of access is enough.
In scope
crawlcheck.io and its subpaths, the public API under /api, report and share links, the lead form script /f.js, the browser extension, and the crawlcheck-core repository.
Please do not
Access, change or delete data that is not yours; run denial-of-service or high-volume automated tests; submit forged leads through another business’s form; use social engineering or physical attacks; or test third-party services we use (Cloudflare, Stripe, Google).
What we will do
Acknowledge your report within three business days, tell you whether we can reproduce it, and keep you informed until it is fixed. We will not pursue legal action against good-faith research that follows this page. With your permission we will credit you when the fix ships.
How this site is run
HTTPS only with HSTS, a restrictive content security policy, and scanner requests that refuse private, loopback and link-local destinations. A licence key is a credential: never paste one into a public issue, screenshot or support thread.