generated: '2026-08-14' method: probed probe: true source: https://api.wappalyzer.com/.well-known/security.txt description: >- Wappalyzer serves a valid, unexpired RFC 9116 security.txt from its API host. It is minimal — a contact address and nothing else. There is no disclosure policy document, no bug bounty, and no safe-harbour statement, so a researcher has a route in but no published terms. security_txt: served: true url: https://api.wappalyzer.com/.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 file: well-known/wappalyzer-security.txt rfc: RFC 9116 fields: contact: mailto:hello@wappalyzer.com canonical: https://api.wappalyzer.com/.well-known/security.txt preferred_languages: en expires: '2027-08-14T13:09:02Z' expired: false signed: false note: >- The Expires value observed on 2026-08-14 was exactly one year out to the second from the fetch time, which indicates the file is generated per request rather than authored and rotated. It is a served document either way. contact: - mailto:hello@wappalyzer.com policy: [] policy_published: false bug_bounty: program: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: none acknowledgements: null hiring: null encryption: null safe_harbour: false gaps: - No Policy field in security.txt and no disclosure-policy page. - Contact is the general company address (hello@), not a dedicated security@ mailbox. - No PGP/encryption key offered for sensitive reports. - No acknowledgements or hall of fame. - >- security.txt is served only from api.wappalyzer.com. The primary web property www.wappalyzer.com answers /.well-known/security.txt with its SPA HTML shell, so a researcher starting at the main site will not find it. evidence: - {source: 'https://api.wappalyzer.com/.well-known/security.txt', kind: security.txt, http_status: 200} - {source: 'well-known/wappalyzer-security.txt', kind: saved-verbatim} - {source: 'https://www.wappalyzer.com/security/', kind: disclosure-page, http_status: 200, detail: 'SPA 404 shell — no page'} - {source: 'https://www.wappalyzer.com/.well-known/security.txt', kind: security.txt, http_status: 200, detail: 'SPA HTML shell, not a document'} - {source: 'https://mcp.wappalyzer.com/.well-known/security.txt', kind: security.txt, http_status: 404} x-evidence: fetched: '2026-08-14'