GZW Data API · Vulnerability Disclosure

Gzw Data Vulnerability Disclosure

Vulnerability disclosure

GZW Data API runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

GamingVideo Gamesgray-zone-warfareGame DataDeveloper ToolsOpen DataOpenAPIWeaponsMissionslootREST APIPublic APIsNo AuthRead OnlyFree APICommunity
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@gzw-data.dev

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-03'
method: searched
probe: true
source: https://gzw-data.dev/.well-known/security.txt + https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md
note: >-
  NEW THIS ROUND. On 2026-08-26 this host served no /.well-known/security.txt (404) and no policy
  page was found, so no disclosure artifact was written. Both now exist and were fetched live on
  2026-09-03: an RFC 9116 security.txt on the production host, and a written Security Policy in the
  source repository. There is no paid bug-bounty program (no HackerOne / Bugcrowd / Intigriti
  listing was found) — this is a private-reporting VDP, which is what a single-maintainer free
  project would be expected to run.
program_type: vulnerability-disclosure-policy
bug_bounty: false
policy:
- url: https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md
  status: 200
  kind: SECURITY.md
contact:
- mailto:security@gzw-data.dev
reporting_channels:
- channel: GitHub private vulnerability reporting
  detail: The policy directs reporters to "the private security reporting channel configured on the GitHub repository".
- channel: email
  detail: security@gzw-data.dev, also published in the docs "Support & security" block and in security.txt.
scope:
  in_scope:
  - the public read-only API
  - the web console
  - deployment configuration
  - the data publication workflow
  out_of_scope:
  - denial-of-service testing
  - quota / rate-limit bypass testing
  - destructive requests
  - systems outside the project
  - data-quality problems (wrong, missing or stale game data) unless they expose a security or privacy problem
requested_report_contents: [description and impact, affected endpoint or commit, reproducible steps or PoC, suggested mitigation]
prohibited_in_reports: [real credentials, tokens, private URLs, personal data]
response_targets:
  published: false
  statement: >-
    "We will acknowledge a report when practicable, validate the issue, communicate an initial
    severity, and coordinate a fix or mitigation. Timelines depend on impact and reproducibility."
    No numeric SLA is committed.
disclosure:
  coordinated: true
  statement: Reporters are asked to allow a reasonable remediation window before public disclosure; credit is offered on request.
security_txt:
  file: well-known/gzw-data-security.txt
  fields_present: [Contact, Expires, Preferred-Languages, Canonical]
  fields_absent: [Policy, Encryption, Acknowledgments, Hiring, CSAF]
  expires: '2027-08-27T00:00:00.000Z'
  gap: >-
    The security.txt carries no Policy: field, so a machine reading only security.txt cannot reach
    the SECURITY.md policy. Adding "Policy: https://github.com/ZoniBoy00/gzw-data/blob/main/SECURITY.md"
    would close that with one line.
evidence:
- url: https://gzw-data.dev/.well-known/security.txt
  status: 200
  fetched: '2026-09-03'
  kind: security.txt
- url: https://raw.githubusercontent.com/ZoniBoy00/gzw-data/main/SECURITY.md
  status: 200
  fetched: '2026-09-03'
  kind: security-policy
- url: https://gzw-data.dev/docs/
  status: 200
  fetched: '2026-09-03'
  kind: docs "Support & security" block naming security@gzw-data.dev for private vulnerability reports

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gzw-data-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.