generated: '2026-08-13' method: searched probe: true source: >- https://raw.githubusercontent.com/plausible/analytics/master/SECURITY.md and live probes of https://plausible.io/vulnerability-disclosure-program and https://plausible.io/security on 2026-08-13 policy: - https://plausible.io/vulnerability-disclosure-program contact: - security@plausible.io bug_bounty: offered: false platform: null detail: >- "While we do not have a bounty program in place yet, we are incredibly thankful for people who take the time to share their findings with us." — SECURITY.md, github.com/plausible/analytics. No HackerOne, Bugcrowd or Intigriti program was found. security_overview: https://plausible.io/security supported_versions: >- "We only add security updates to the latest MAJOR.MINOR version of the project. No security updates are backported to previous versions." — SECURITY.md security_txt: served: false detail: >- /.well-known/security.txt probed 2026-08-13 and returned HTTP 404. The disclosure program is published as an ordinary HTML page and in the repo's SECURITY.md instead of as an RFC 9116 document, so no SecurityTxt pointer is emitted. This is the one cheap fix available to Plausible here: the policy and contact already exist, they are simply not machine-discoverable. evidence: - {source: 'https://raw.githubusercontent.com/plausible/analytics/master/SECURITY.md', kind: security-policy, http_status: 200, fetched: '2026-08-13'} - {source: 'https://plausible.io/vulnerability-disclosure-program', kind: disclosure-page, http_status: 200, fetched: '2026-08-13'} - {source: 'https://plausible.io/security', kind: security-overview, http_status: 200, fetched: '2026-08-13'} - {source: 'https://plausible.io/.well-known/security.txt', kind: security.txt, http_status: 404, fetched: '2026-08-13'} note: >- The mechanical probe (0-working/probe-security-programs.py) reported vdp=none for this provider on 2026-08-13. That is a false negative: the disclosure program and the security@ contact are genuinely published, they are just not at any of the conventional paths the probe checks (/security/responsible-disclosure, /responsible-disclosure, /vulnerability-disclosure) — Plausible uses /vulnerability-disclosure-program. This file is therefore method: searched with the URLs and statuses recorded above. maintainers: - FN: Kin Lane email: kin@apievangelist.com