Report a vulnerability
If you find a security issue in a system we operate, tell us. We read every good-faith report. A reward is our decision, and we pay it only after we confirm the issue.
Developer resourcesRewards
The figures are upper bounds, not a quote. We set the amount after we reproduce the issue. We pay the first valid report. We may pay less, or nothing, when the impact is narrow, the report is incomplete, or we already knew.
Critical
Up to €3,000
Remote code execution, or a bypass that exposes other customers’ data without their credentials.
Up to €3,000
High
Up to €1,000
Access to another customer’s data while signed in, or a step up to an administrator.
Up to €1,000
Medium
Up to €500
Cross-site scripting or cross-site request forgery on an action that changes data, when the impact is realistic.
Up to €500
Low
Up to €100
A small information leak or an open redirect, when you can show the impact.
Up to €100
Notes without a demonstrated impact — missing headers, scanner output, best-practice comments — are welcome and are not paid. We pay in euros or USDT, after we accept the report, usually within 30 days.
What you can test
Only systems we operate, and only with an account you own. If a test would expose or change someone else’s data, stop and describe what you already saw.
- The public site, www.thepowerplugin.com.
- The operations app at app.thepowerplugin.com, with your own account.
- The rewards API, hosted storefront and MCP endpoint on hosts we operate, including the documented sandbox.
How to test
- Go only as far as you need to show the impact.
- Do not degrade the service. No denial of service, flooding or password guessing.
- Do not phish staff, customers or suppliers, and do not attempt physical access.
- Do not access, change or download data that is not yours. Your own account is enough to demonstrate an issue.
- Wait 90 days from your report before you publish anything, unless we agree to a shorter window.
- Send one issue per report.
Out of scope
- Denial of service, and automated scanning that puts load on the service.
- Social engineering and physical attacks.
- Third parties we do not operate: payments, email delivery, hosting status pages. Report those to the vendor.
- Missing headers, cookie flags or email authentication records, without a working impact.
- Self-XSS, clickjacking on a page with no sensitive action, and logout CSRF.
- Anything that needs stolen credentials, or access you were not given.
What happens next
- 01
We acknowledge a complete report within 5 business days.
- 02
We aim to tell you whether it qualifies within 10 business days.
- 03
We credit you by name only if you ask. Please wait 90 days before any public write-up.
Good faith
If you follow this policy, we will not take legal action over your research. This is not permission to attack systems we do not operate, or to keep testing once the impact is clear. Reports that break these rules are outside the program.
Known reports
Issues we have confirmed. We name who found them and, if there was a reward, the amount. We do not describe how they worked.
Sep 23, 2026 · High
Exposed credentials in a legacy system
Thanks to Mateo and Antonio.
€1,000
Aug 30, 2026 · Low
File type validation on image uploads
Thanks to Adrian.
