OptinMonster · Vulnerability Disclosure

Optinmonster Vulnerability Disclosure

Vulnerability disclosure

OptinMonster runs a coordinated vulnerability disclosure program on Hackerone.

CompanyLead GenerationMarketingConversion OptimizationEmail MarketingPopupsWordPressWebhookSoftware-as-a-ServiceMarketing Automation
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

optinmonster-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://optinmonster.com/security/
note: >-
  OptinMonster publishes a "Security and Reliability Safeguards" page carrying a role-address
  security contact. That is a real, published intake channel, so this artifact is written and a
  `Security` pointer is wired in apis.yml. It is however the weakest form of the surface: there is
  no policy text, no safe-harbour statement, no scope, no response-time commitment, no PGP key, and
  no RFC 9116 security.txt at any well-known location on any host (all probed — see
  well-known/optinmonster-well-known.yml). There is no bug bounty program: HackerOne, Bugcrowd and
  Intigriti carry no OptinMonster or Awesome Motive program.
disclosure:
  channel: email
  contact: security@optinmonster.com
  contact_source: >-
    Published on https://optinmonster.com/security/ under "If you have any security concerns or
    questions feel free to contact us". The address is obfuscated on the page by Cloudflare email
    protection; decoded from the page's own `data-cfemail` attribute.
  policy_published: false
  policy_url: null
  safe_harbor: false
  scope_defined: false
  response_sla: null
  pgp_key: false
  encryption: false
  preferred_languages: null
security_txt:
  served: false
  rfc9116: false
  probes:
  - url: https://optinmonster.com/.well-known/security.txt
    http_status: 404
  - url: https://api.optinmonster.com/.well-known/security.txt
    http_status: 301
  - url: https://app.optinmonster.com/.well-known/security.txt
    http_status: 301
  - url: https://api.omwpapi.com/.well-known/security.txt
    http_status: 301
  fetched: '2026-08-12'
bug_bounty:
  exists: false
  platform: null
  programs_checked:
  - hackerone
  - bugcrowd
  - intigriti
  note: No public program found for OptinMonster or its parent, Awesome Motive.
published_safeguards:
  note: >-
    Recorded verbatim as vendor claims from the security page. These are infrastructure assertions,
    not audited controls, and none is backed by a named certification.
  claims:
  - 256-bit SSL encryption for data in transit
  - Sucuri vulnerability monitoring and scanning
  - Amazon infrastructure for redundant storage and servers
  - Pagely hosting (Amazon partner)
  - Bunny.net CDN
  - Geographic data replication across multiple locations
certifications:
  soc2: false
  iso27001: false
  pci_dss: false
  hipaa: false
  fedramp: false
  note: >-
    No named certification appears anywhere on the security page, the GDPR page, or the site. No
    trust center exists — trust.optinmonster.com returns 501 and optinmonster.com/trust/ is a
    product review article, not a compliance surface. No `Compliance` or `TrustCenter` pointer is
    emitted.
x-evidence:
  fetched: '2026-08-12'
  url: https://optinmonster.com/security/
  http_status: 200
gaps:
- No RFC 9116 security.txt on any host.
- No written disclosure policy, scope, or safe-harbour statement.
- No response-time commitment for reported vulnerabilities.
- No PGP key or encrypted submission channel.
- No bug bounty or coordinated disclosure program.
- No named security certification and no trust center.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/optinmonster-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.