Dotdash Meredith / People Inc · Vulnerability Disclosure
Meredith Vulnerability Disclosure
Vulnerability disclosure
People Inc (formerly Dotdash Meredith) runs a PRIVATE, invitation-only HackerOne program for coordinated vulnerability disclosure. It is advertised the correct way — an RFC 9116 /.well-known/security.txt served at HTTP 200 as text/plain from the consumer brand domains — but the program itself is not publicly enumerable.
Dotdash Meredith / People Inc runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
MediaPublishingMagazinesContentAdvertisingContextual AdvertisingLifestyleNewsRSSSitemapRobotsAI PolicyIaC
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
{"http_status" => 200, "kind" => "HackerOne embedded submission form", "note" => "This DOES resolve. An unauthenticated researcher can file a report\nthrough the embedded form without a HackerOne account invitation, so\nthe intake path works even though the policy page does not.\n", "reachable" => true, "url" => "https://hackerone.com/b6bf1613-5ba4-4ce3-b371-ac47e4507b5d/embedded_submissions/new"}