CrawlCheck

Security

Reporting a security problem

If you find a vulnerability in crawlcheck.io, its API, the browser extension or the published scanner code, email hello@crawlcheck.io with the subject line Security report. The machine-readable version of this page is security.txt.

What to include

The URL or endpoint, the steps to reproduce it, what an attacker gains, and whether you believe any data belonging to someone else was exposed. A proof of concept that stops at the first sign of access is enough.

In scope

crawlcheck.io and its subpaths, the public API under /api, report and share links, the lead form script /f.js, the browser extension, and the crawlcheck-core repository.

Please do not

Access, change or delete data that is not yours; run denial-of-service or high-volume automated tests; submit forged leads through another business’s form; use social engineering or physical attacks; or test third-party services we use (Cloudflare, Stripe, Google).

What we will do

Acknowledge your report within three business days, tell you whether we can reproduce it, and keep you informed until it is fixed. We will not pursue legal action against good-faith research that follows this page. With your permission we will credit you when the fix ships.

How this site is run

HTTPS only with HSTS, a restrictive content security policy, and scanner requests that refuse private, loopback and link-local destinations. A licence key is a credential: never paste one into a public issue, screenshot or support thread.