Fluxer

Fluxer

Top 1M site
Bug BountyActiveBounty Recognition

Program Details

Fluxer may award a Bug Hunter badge and Fluxer Plutonium gift codes for valid reports.

Rules & Testing

Excluded Methods

DosSocial EngineeringPhishingPhysical AccessAutomated Scanning

In-Scope Domains

  • *.fluxer.app
  • *.fluxer.gg
  • *.fluxer.gift
  • *.fluxerapp.com
  • *.fluxer.dev
  • *.fluxerusercontent.com
  • *.fluxerstatic.com
  • *.fluxer.media

Out of Scope

Third-party services and infrastructure we do not control, including partner communities' independent integrations, bots, and external hosting providers., Physical security, Social engineering, Phishing, Bribery, Coercion, Attempts to manipulate Fluxer staff or users are also out of scope., DoS attacks, Traffic flooding, Resource exhaustion testing, Noisy automated scanning, Bulk testing without a clear impact, General UI bugs, Feature requests and ordinary support issues are out of scope, Application-layer DoS vulnerabilities that can be demonstrated with a single unauthenticated request or a small number of requests may be reported, but do not actively exploit them at scale., Issues in forked, modified, or outdated self-hosted deployments are out of scope unless they are reproducible on the latest official release. Low-impact or theoretical findings, such as missing best-practice headers, are usually not prioritised unless you can show a realistic attack path and concrete security impact.

Security

Preferred Languages
English

security.txt

Contact
https://fluxer.app/security, mailto:[email protected]
Policy
https://fluxer.app/security
Languages
en
Expires
Sep 9, 2028
View raw security.txt →