Wappalyzer · Vulnerability Disclosure
Wappalyzer Vulnerability Disclosure
Vulnerability disclosure
Wappalyzer serves a valid, unexpired RFC 9116 security.txt from its API host. It is minimal — a contact address and nothing else. There is no disclosure policy document, no bug bounty, and no safe-harbour statement, so a researcher has a route in but no published terms.
Wappalyzer runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Technology DetectionTechnographicsWebsite AnalysisCMS DetectionFramework DetectionLead EnrichmentSales IntelligenceSubdomain DiscoveryEmail VerificationMarket Research
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:hello@wappalyzer.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.