generated: '2026-09-07' method: searched source: https://bugcrowd.com/adoreme-vdp program: name: Adore Me Vulnerability Disclosure Program platform: Bugcrowd type: vulnerability-disclosure tier: VDP Pro url: https://bugcrowd.com/adoreme-vdp managed: true rewards: false note: >- A Bugcrowd-managed Vulnerability Disclosure Program (not a paid bug bounty). Bugcrowd describes the engagement as using the Bugcrowd Vulnerability Rating Taxonomy for initial prioritization, with a documented appeal path when a submission is downgraded, and Bugcrowd's standard disclosure terms. The program is discoverable from a "Report a vulnerability" link in the adoreme.com site footer. discovery: - surface: adoreme.com footer link_text: Report a vulnerability target: https://bugcrowd.com/adoreme-vdp security_txt: published: false probed: - url: https://www.adoreme.com/.well-known/security.txt status: 404 - url: https://adoreme.com/.well-known/security.txt status: 404 note: >- Adore Me runs a real disclosure program but does not advertise it in an RFC 9116 security.txt at either the apex or www host. A researcher who follows the standard discovery path finds nothing; the program is only reachable by reading the rendered site footer. Publishing a /.well-known/security.txt with a Policy: line pointing at https://bugcrowd.com/adoreme-vdp would close that gap with a single static file, and is the single cheapest security-surface improvement available to this company. no_securitytxt_pointer: >- No `SecurityTxt` pointer is wired in apis.yml, because no security.txt is served. A `Security` pointer IS wired, pointing at the Bugcrowd program, which is real. safe_harbor: stated: unknown note: >- The Bugcrowd brief page renders its scope, safe-harbor and reward terms client-side and gates the full brief behind a researcher login, so the safe-harbor language could not be read anonymously and is not asserted here. scope: targets: unknown note: >- In-scope targets are published inside the Bugcrowd brief, which is not readable without a Bugcrowd account. Not recorded rather than guessed. x-evidence: - url: https://bugcrowd.com/adoreme-vdp http_status: 200 fetched: '2026-09-07' - url: https://www.adoreme.com/.well-known/security.txt http_status: 404 fetched: '2026-09-07' - url: https://www.adoreme.com/ http_status: 200 fetched: '2026-09-07' note: Footer carries the "Report a vulnerability" link to the Bugcrowd program.