Responsible reports are welcome.
The project is intentionally low-complexity, but low complexity is not the same as zero security risk. If you find a genuine vulnerability in a project web property, please report it privately.
Scope and boundaries
Good-faith testing should be limited to the public web applications that are clearly part of Sweden, clearly.
- Do not perform denial-of-service or high-volume automated testing.
- Do not access, modify or retain data that is not yours.
- Do not use social engineering, phishing or physical attacks.
- Do not test unrelated mail services, hosting-provider infrastructure or third-party services merely because they share infrastructure or DNS.
- Stop when you have enough evidence to explain the problem.
No bug bounty: this is a non-commercial one-person project. There is no reward programme and no guaranteed response time.
What to include
- affected hostname and URL;
- clear reproduction steps;
- impact in plain language;
- minimal proof of concept;
- your preferred contact method, if you want a reply.
security.txt
The project publishes /.well-known/security.txt following RFC 9116 ↗. Because a security.txt file is scoped to the hostname from which it is retrieved, serving the shared file on each project vhost provides a contact point on each hostname.
The file’s expiry date needs occasional maintenance; RFC 9116 recommends an expiry less than a year into the future.