LinkPeek · Vulnerability Disclosure

Linkpeek Vulnerability Disclosure

Vulnerability disclosure

LinkPeek runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

screenshotswebpage-capturewebsite-thumbnailsimage-generationrenderingweb-scraping-adjacentdeveloper-toolssaasrest-image-apiDeveloper ToolsUtility APIURL MetadataLink PreviewOpenGraphQR Code GenerationDNSWHOISSSLWeb Security ScanningIP GeolocationData ConversionLLM-Compatible APIapi-utilitiesurl-metadatalink-previewqr-code-generationdns-whoisweb-security-scanningdata-conversionopenai-compatible-llm
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://github.com/dcn13l/hermes-autonomia/security/advisories/new
Contact
https://github.com/dcn13l/hermes-autonomia/issues/new?template=security_report.yml

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-09'
method: searched
probe: true
source: https://github.com/dcn13l/hermes-autonomia
note: >-
  There is no security.txt and no security page on either host — the mechanical probe found
  nothing (`vdp=none`). The disclosure channel LinkPeek actually publishes lives in the source
  repository: a private-reporting route via GitHub Security Advisories, wired into the repo's
  issue-template config so it is surfaced to anyone opening an issue, plus a public
  security-report template for non-critical findings. That is a real, documented,
  publicly-reachable vulnerability-reporting path, so it is recorded here.
policy:
  - https://github.com/dcn13l/hermes-autonomia/security/advisories/new
contact:
  - https://github.com/dcn13l/hermes-autonomia/security/advisories/new
  - https://github.com/dcn13l/hermes-autonomia/issues/new?template=security_report.yml
bug_bounty:
  program: null
  paid: false
  note: 'No HackerOne, Bugcrowd or Intigriti program; no bounty offered.'
security_txt: false
disclosure_guidance: >-
  The repository instructs reporters that critical, actively exploitable vulnerabilities should be
  filed privately through GitHub Security Advisories so fixes can ship before disclosure, and that
  reports must not include live secrets, API keys or credentials. Non-critical hardening findings
  go to the public security issue template, which asks for a severity estimate and a category
  (SSRF, auth/authorization bypass, rate-limit bypass, injection, information disclosure,
  dependency vulnerability).
evidence:
  - source: https://github.com/dcn13l/hermes-autonomia/blob/main/.github/ISSUE_TEMPLATE/config.yml
    kind: issue-template-config
    http_status: 200
    detail: 'contact_links entry "Report a Security Vulnerability" → GitHub Security Advisories'
  - source: https://github.com/dcn13l/hermes-autonomia/blob/main/.github/ISSUE_TEMPLATE/security_report.yml
    kind: security-issue-template
    http_status: 200
    detail: 'Public security report form with severity and category taxonomy and private-disclosure guidance'
  - source: https://147.15.103.217.sslip.io/.well-known/security.txt
    kind: security.txt
    http_status: 404
  - source: https://linkpeek.com/.well-known/security.txt
    kind: security.txt
    http_status: 404
gaps:
  - No RFC 9116 /.well-known/security.txt on either host.
  - No SECURITY.md at the repository root.
  - No stated response-time or safe-harbour commitment.