All checks

Security.txt

The security.txt file, and who it says to contact about vulnerabilities

What it is

security.txt tells researchers how to report a security problem. RFC 9116 defines the format: a contact address at minimum, then optionally a disclosure policy, a PGP key, preferred languages and an expiry date. It belongs at /.well-known/security.txt.

Why it matters

Without a published contact, whoever finds a vulnerability either gives up or reports it somewhere public. The file is informative in its own right: a current, complete one suggests a team that expects reports, and the PGP key carries metadata of its own.

Related checks