Vulnerability Disclosure
If you have found a security issue in the PlugMonkey website or in one of our Chrome extensions, we want to hear about it. This page explains what to test, how to report it, and what we commit to in return.
Reporting an issue
Send security reports through our contact form using the Security Vulnerability Report subject. The link below fills that in and gives you a short template to complete. Please include what you found, how to reproduce it, and what you believe the impact is.
Report a security issueIf a proof of concept would touch real customer data, describe it rather than carrying it out. A clear written explanation is enough for us to act on.
What is in scope
Some context that will save you time: this website is a static site. It has no user accounts, no login, no server-side application code, and no database. Payments and license delivery are handled by Lemon Squeezy, not by us. The interesting surface is therefore our extensions and the licensing endpoint rather than the marketing pages.
- The plugmonkey.xyz website and its subdomains.
- Our published Chrome extensions, including their popup, options, and in-page interfaces.
- Our licensing endpoint and the way extensions communicate with it.
- Anything that exposes another customer's data, license key, or purchase information.
What is out of scope
- Third-party services we use but do not operate: Lemon Squeezy (payments), Kit (email), PostHog (analytics), and the Chrome Web Store. Report issues in those to their own security teams — we cannot authorise testing against systems we do not control.
- Reports generated purely by an automated scanner, with no demonstrated impact. Header and TLS configuration findings are welcome, but tell us what an attacker could actually do.
- Denial of service, traffic flooding, or anything that degrades the service for real customers.
- Social engineering of us, our customers, or anyone reviewing our extensions.
- Missing security headers or best-practice recommendations with no exploitable consequence. We may still fix these, but they are not vulnerabilities.
What to expect from us
Timelines, honestly
PlugMonkey is a small independent operation, not a company with a security team on rotation. We would rather tell you that than promise a response time we cannot keep.
- We aim to acknowledge every report within five business days, and we read all of them.
- We will tell you whether we consider it a vulnerability, and why, rather than going quiet.
- We will keep you updated while we work on a fix, and let you know when it ships.
- We are happy to credit you publicly when the issue is resolved, if you want that.
Safe harbour
Our commitment to you
If you make a good-faith effort to follow this policy while researching and reporting an issue, we will not pursue or support legal action against you for that research, and we will not ask your internet provider or employer to act against you. We will treat your report as an attempt to help. If someone else brings a claim against you for activity that followed this policy, tell us and we will make it clear that your research was authorised.
Rules of engagement
Safe harbour above applies as long as your testing stays inside these lines:
- Only test against your own accounts, your own devices, and your own data.
- If you come across someone else's personal data, license key, or purchase record, stop, do not save it, and tell us what you saw in the report.
- Use the minimum access needed to demonstrate the issue. Do not modify or delete anything that is not yours.
- Give us a reasonable chance to fix the issue before discussing it publicly.
- Do not run scans or automated tooling at a volume that would affect other people using the site.
Rewards
We do not run a paid bug bounty programme, and we would rather say so plainly than leave you guessing. What we can offer is a real response from the person who maintains the code, public credit if you want it, and a fix. If you report something genuinely serious, get in touch about it and we will work out something fair.
Machine-readable version
We publish an RFC 9116 security.txt with our current contact details and a pointer back to this page.
/.well-known/security.txt