We appreciate the security research community. If you discover a vulnerability in PLZ FRUIT, please report it privately using the process below. We will not pursue legal action against researchers who follow this policy in good faith.
1. In Scope
- The PLZ FRUIT web application on our official domains.
- API endpoints used by the Site.
- Authentication, authorization, and account-management flows.
2. Out of Scope
- Denial-of-service, volumetric attacks, or stress tests.
- Social engineering of staff, users, or third-party vendors.
- Physical attacks against our infrastructure.
- Reports based solely on automated scanner output without proof of impact.
- Findings on third-party services (e.g. our hosting provider) — please report those to the vendor.
3. Rules of Engagement
- Only test against accounts you own.
- Do not access, modify, or delete data belonging to other users.
- Do not run automated scanners that generate high traffic.
- Give us a reasonable time to fix the issue before public disclosure.
4. How to Report
Send a detailed report through the contact channels in your account settings or via our support Discord's private security channel. Please include:
- A clear description of the vulnerability.
- Steps to reproduce, ideally with a proof-of-concept.
- Your assessment of impact and affected endpoints.
- Any relevant screenshots, logs, or request captures.
5. Our Commitment
- We will acknowledge valid reports promptly.
- We will keep you updated on remediation progress.
- We will credit researchers on request once the issue is resolved.
6. Safe Harbor
Good-faith security research under this policy is authorized, and we will not initiate legal action against researchers who comply. If a third party pursues legal action, we will make it clear that your activity was authorized.