// Security
Vulnerability disclosure policy
Found a security issue in md-5.com? Thank you. Here’s how to report it and what to expect.
MD-5 takes the security of this website seriously, and welcomes reports from anyone who finds a weakness in it. This policy covers what you may test, how to report what you find, and the commitments made in return. It is also published in machine-readable form at /.well-known/security.txt.
How to report
Email [email protected] with the subject line “Security report”. Please include:
- The URL or component affected, and the type of issue.
- Step-by-step instructions to reproduce it, and any proof-of-concept.
- What an attacker could achieve, as you understand it.
- Whether, and how, you would like to be credited.
If you need to share something sensitive, say so in your first email and an encrypted channel will be set up.
Scope
In scope: the website at md-5.com and the pages and files it serves.
Out of scope:
- Third-party services the site relies on, such as its hosting, email and scheduling providers. Report those to the provider directly.
- Denial-of-service, load testing, or anything that degrades the site for other visitors.
- Social engineering, phishing, or physical attacks.
- Spam or high-volume submissions through the contact form.
- Findings with no demonstrable security impact, such as missing best-practice headers on non-sensitive responses, clickjacking on pages without state-changing actions, or unconfirmed automated scanner output.
Rules for testing
- Only test against this website, and only as much as needed to confirm the issue.
- Don’t access, change or delete data that isn’t yours, and stop as soon as you reach any.
- Don’t run automated scanners that generate heavy traffic.
- Give reasonable time to fix the issue before disclosing it publicly.
What you can expect
- An acknowledgement within one business day, or sooner.
- An assessment of your report, and updates as it’s investigated and fixed.
- Public credit once it’s fixed, if you want it.
This is a disclosure policy, not a paid bug bounty: there is no monetary reward. But good-faith reports are always appreciated.
Safe harbor
If you make a good-faith effort to follow this policy, MD-5 will consider your research authorized, will not pursue or support legal action against you for it, and will work with you to understand and fix the issue quickly. If you’re unsure whether something is allowed, ask first.
This policy applies only to md-5.com. It does not authorize testing of any client system or any other system; penetration testing engagements are always governed by a separate, signed authorization.
Last updated: October 2, 2026