Skip to content

Security: whonion/whonion.dev

Security

SECURITY.md

Security Policy

Supported Versions

We actively support the latest version of whonion.dev. Security updates are applied to the main branch.

Version Supported
Latest
< Latest

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue. Instead, please report it privately:

Email

Send a detailed report to: contact@whonion.app

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Time

  • Initial Response: Within 48 hours
  • Status Update: Within 7 days
  • Resolution: Depends on severity and complexity

Security Best Practices

When reporting vulnerabilities, please:

  1. Do not exploit the vulnerability beyond what is necessary to demonstrate it
  2. Do not access or modify data that does not belong to you
  3. Do not disrupt our services or other users
  4. Do provide detailed information to help us understand and reproduce the issue

Disclosure Policy

  • We will acknowledge receipt of your report within 48 hours
  • We will keep you informed of our progress
  • We will credit you in our security advisories (unless you prefer to remain anonymous)
  • We will not take legal action against security researchers who act in good faith

Scope

In Scope

  • Security vulnerabilities in the website codebase
  • Authentication and authorization issues
  • Data exposure or leakage
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Server-side request forgery (SSRF)
  • SQL injection (if applicable)
  • Remote code execution

Out of Scope

  • Denial of service (DoS) attacks
  • Social engineering attacks
  • Physical security issues
  • Issues requiring physical access to devices
  • Issues in third-party services or dependencies (please report to the respective maintainers)

Recognition

We appreciate responsible disclosure and will recognize security researchers who help us improve the security of whonion.dev. Recognition may include:

  • Credit in our security advisories
  • Public acknowledgment (with your permission)

Thank you for helping keep whonion.dev secure!

There aren’t any published security advisories