BestPrice Agent Commerce · Vulnerability Disclosure
Bestprice Vulnerability Disclosure
Vulnerability disclosure
BestPrice Agent Commerce runs a coordinated vulnerability disclosure program on Hackerone.
ShoppingPrice ComparisonE-CommerceRetailMCPWebMCPAgent CommerceGreece
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-27'
method: searched
source: https://www.bestprice.gr/.well-known/security.txt (HTTP 200, text/plain, fetched 2026-08-27)
and https://github.com/TheBestCo/bestprice-mcp/blob/main/SECURITY.md (HTTP 200).
docs: https://github.com/TheBestCo/bestprice-mcp/blob/main/SECURITY.md
program_published: true
program_type: coordinated-disclosure
bug_bounty: false
bug_bounty_platform: null
note: >-
A real, current disclosure route exists in both machine-readable and human-readable form. The
automated probe (probe-security-programs.py) recorded vdp=none because security.txt carries no
Policy: field and no HackerOne/Bugcrowd/Intigriti platform is used — but the Contact is live, the
Expires date is in the future, and SECURITY.md sets out a full reporting procedure. Recorded here as
searched, on that evidence.
security_txt:
url: https://www.bestprice.gr/.well-known/security.txt
status: 200
file: bestprice-security.txt
path: ../well-known/bestprice-security.txt
fields:
contact: https://www.bestprice.gr/contact
expires: '2027-07-31T23:59:59Z'
expires_in_future: true
preferred_languages: [el, en]
canonical: https://www.bestprice.gr/.well-known/security.txt
policy: null
encryption: null
acknowledgments: null
hiring: null
rfc9116_valid: true
also_served_at:
- url: https://mcp.bestprice.gr/.well-known/security.txt
status: 200
note: Byte-identical; both hosts point at the same Canonical.
disclosure_policy:
url: https://github.com/TheBestCo/bestprice-mcp/blob/main/SECURITY.md
status: 200
channels:
- {type: email, value: feedback@bestprice.gr, subject_convention: 'MCP security report'}
- {type: web, value: 'https://www.bestprice.gr/contact'}
no_public_issue: true
requested_report_contents:
- affected URL or tool
- clear reproduction steps
- observed impact
- any request IDs the service returned
- a safe contact channel for the reporter
prohibited:
- credentials
- payment-card data
- unnecessary personal data
- live exploit traffic against other users
supported_versions: >-
Only the current production version of the hosted service at https://mcp.bestprice.gr/mcp. The
repository manifests describe that hosted service and are not a separately hosted implementation.
safe_harbor_stated: false
gaps:
- No Policy: field in security.txt, so a machine reading only that file finds a contact but no terms.
- No stated safe harbour for good-faith researchers.
- No bug bounty, acknowledgments page or PGP key.
- No published remediation SLA or triage timeline.
x-evidence:
- url: https://www.bestprice.gr/.well-known/security.txt
status: 200
- url: https://mcp.bestprice.gr/.well-known/security.txt
status: 200
- url: https://github.com/TheBestCo/bestprice-mcp/blob/main/SECURITY.md
status: 200
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bestprice-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.