# PlugMonkey security contact — RFC 9116 # # If you have found a security issue in the PlugMonkey website or in any of # our Chrome extensions, please report it through the contact form linked # below, using the "Security Vulnerability Report" subject. We will # acknowledge your report and keep you updated while we investigate. # # Please include: what you found, how to reproduce it, and what impact you # think it has. If a proof of concept touches real user data, describe it # rather than exercising it. # # WHY A URL RATHER THAN A mailto: # RFC 9116 accepts any URI for Contact, not just mailto:. A web form is used # deliberately here for two reasons. First, publishing an address in a file # designed to be crawled is a standing invitation to scrapers, and a security # inbox that fills with spam is one where a real report gets missed. Second, # plugmonkey.xyz has no MX records yet, so any @plugmonkey.xyz address in this # file would silently bounce — and a security contact that bounces is worse # than publishing no file at all, because a researcher who cannot reach us # discloses publicly instead. The form reaches us regardless of mail setup. # # Expires is a required field under RFC 9116, and an expired file is treated # as invalid — so this needs renewing before the date below. Contact: https://plugmonkey.xyz/support/?subject=Security%20Vulnerability%20Report Policy: https://plugmonkey.xyz/security/ Expires: 2027-09-10T00:00:00.000Z Preferred-Languages: en Canonical: https://plugmonkey.xyz/.well-known/security.txt