If you find a security issue in this scanner, please email contact@toughlovesec.win with:
- A description of the issue
- Steps to reproduce (or a proof-of-concept)
- Your assessment of severity
Please do not open a public issue, post to social media, or demonstrate the vulnerability against systems you do not own.
- Acknowledgement within 72 hours
- Status update within 7 days
- Coordinated disclosure timeline: 90 days from initial report, or earlier if a patch ships and is adopted
We do not currently offer a paid bug bounty, but we credit reporters in release notes unless you request anonymity.
server.js— the HTTP wrapper (auth bypass, RCE, path traversal, SSRF)scan.shandscanners/*.sh— the scan orchestrator (command injection via target URL, payload handling)Dockerfile/fly.toml— deployment hardening concerns
- Findings produced by the scanner on third-party sites
- Denial-of-service against the scanner itself via malformed input (file issues for these)
- Social engineering, physical attacks
This tool sends active payloads. Only scan systems you own or have written authorization to test. Unauthorized scanning is illegal in most jurisdictions. We are not responsible for misuse.