Security Research Challenge

Part bug bounty, part capture-the-flag

This isn't your typical bug bounty. We've built something for researchers who appreciate the craft. Real vulnerabilities earn real rewards. There's also an Easter egg for those who understand the history of authentication security. No scanners. No spray-and-pray. Just you, the API, and your knowledge.

Rewards

Scope

Rules of Engagement

Out of Scope

How It Works

Safe Harbor

Security research conducted in accordance with this policy is authorized. We will not pursue legal action against researchers acting in good faith.

Getting Started

Our bug bounty program is private on HackerOne. To request an invitation, email [email protected] with your HackerOne username and areas of interest. We review requests weekly and prioritize researchers with authentication security experience.

WordPress, done right.

€15/year. Not a typo.

For developers, agencies, and creators who refuse to overpay.

Get Started

Cancel anytime · 30-day money-back guarantee