Moz · Vulnerability Disclosure

Moz Vulnerability Disclosure

Vulnerability disclosure

Moz runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

SEOSearchMarketingAnalyticsKeywordsBacklinksLocal MarketingDomain AuthorityLink IndexJSON-RPCMCPCompany
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
{"kind" => "email", "source" => "Contact: field of https://moz.com/.well-known/security.txt", "status" => "live (address, not probed for delivery)", "value" => "inboundeng+cms@moz.com"}

Source

Vulnerability Disclosure

moz-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: probed
source: https://moz.com/.well-known/security.txt
document: well-known/moz-security.txt
summary: >-
  Moz serves a real RFC 9116 security.txt at https://moz.com/.well-known/security.txt (HTTP 200) with
  a working contact address, so a reporter has somewhere to send a finding. Every other field in that
  document, however, points at a page that no longer exists, and the document itself was expired at
  the time of probing.
program_type: security.txt contact only
bug_bounty:
  published: false
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  found: none
contact:
- kind: email
  value: inboundeng+cms@moz.com
  source: 'Contact: field of https://moz.com/.well-known/security.txt'
  status: live (address, not probed for delivery)
policy:
- url: https://moz.com/security-policy
  advertised_in: 'Policy: field of security.txt'
  http_status: 404
  checked: '2026-08-26'
  note: The advertised security policy page is not served.
encryption:
- url: https://moz.com/pgp-key.txt
  advertised_in: 'Encryption: field of security.txt'
  http_status: 404
  checked: '2026-08-26'
acknowledgements:
- url: https://moz.com/hall-of-fame
  advertised_in: 'Acknowledgements: field of security.txt'
  http_status: 404
  checked: '2026-08-26'
expiration:
  value: '2026-08-25T19:48:09-07:00'
  expired: true
  checked: '2026-08-26'
  note: >-
    RFC 9116 requires the Expires field and says a document past its expiry should be considered
    stale. This one lapsed one day before probing.
evidence:
- url: https://moz.com/.well-known/security.txt
  status: 200
- url: https://moz.com/security-policy
  status: 404
- url: https://moz.com/pgp-key.txt
  status: 404
- url: https://moz.com/hall-of-fame
  status: 404
finding: >-
  Three of the five advertised URLs in Moz's security.txt are dead and the document has expired.
  This is a small, cheap, provider-side fix - restore or remove the Policy, Encryption and
  Acknowledgements lines and roll the Expires date forward - and it is worth flagging back to Moz
  rather than scoring silently.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/moz-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.