GoatCounter · Vulnerability Disclosure
Goatcounter Vulnerability Disclosure
Vulnerability disclosure
GoatCounter serves a real security.txt, but at the legacy document-root path /security.txt rather than the RFC 9116 canonical /.well-known/security.txt, which is why the mechanical probe-security-programs.py pass reported vdp=none — it checks the canonical path. The document is minimal: one Contact line and nothing else. There is no bug bounty, no named disclosure policy page, and no PGP key.
GoatCounter runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
AnalyticsPage ViewsPrivacyStatisticsWeb AnalyticsOpen-SourceSelf-HostedEventData ExportDeveloper Tools
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
support@goatcounter.com