Skip to content

Start typing to search

Security: Reporting a Vulnerability

How to report a security vulnerability on pingeverything.com: what is in scope, where to write, what we promise in return, and what falls outside this channel.

Last updated

If you have found a vulnerability on this site, we would like to hear about it, and we will take it seriously.

Scope

This channel covers pingeverything.com and its pages. The platforms the site runs on (hosting, analytics and advertising services) are outside our scope; issues in those belong with the provider concerned, though a heads-up is still welcome.

The sister site sercebilisim.com is run separately and publishes its own policy.

How to report an issue

Write to info@sercebilisim.com, the same address as on the contact page. To help us verify quickly, please include:

  • The page where you found the issue.
  • Steps to reproduce it, with a screenshot or a request and response sample if you have one.
  • Your assessment of the potential impact.

The machine-readable contact file is published at /.well-known/security.txt (RFC 9116).

What we promise

  • We read every report and reply as soon as we can.
  • We fix confirmed issues and keep you informed along the way.
  • Once an issue is resolved, we are happy to credit you by name; staying anonymous is equally fine.
  • We treat good-faith research that does not harm data or disrupt the service as a contribution, not a threat.

There is no bug bounty.

Out of scope

The following are not treated as reports through this channel:

  • Denial-of-service attempts and high-volume automated scanning.
  • Social engineering, phishing and physical-access scenarios.
  • Raw scanner output and version disclosures without a demonstrated vulnerability.
  • Best-practice suggestions on their own, such as a missing header. You are still welcome to write, but we will ask for evidence of impact.