Skip to content

Security: xPloits3c/DorkEye

Security

.github/SECURITY.md

Security Policy 🛡️

Supported Versions

We actively provide security updates for the following versions of DorkEye:

Version Supported
1.x
< 1.0

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

If you discover a potential security jump or vulnerability within DorkEye, we want to fix it as soon as possible. Please report it privately by following these steps:

  1. Email us: Send a detailed report to [IL TUO INDIRIZZO EMAIL QUI].
  2. Describe the bug: Include steps to reproduce, the potential impact, and any proof-of-concept (PoC) code.
  3. Response time: We will acknowledge your report within 48-72 hours and provide a timeline for a fix.

What we consider a security vulnerability:

  • Remote Code Execution (RCE) in the tool's logic.
  • Unintended exposure of sensitive user data or API keys.
  • Vulnerabilities in third-party dependencies used by DorkEye.

Disclosure Policy

We follow a coordinated disclosure policy. Please give us a reasonable amount of time to fix the issue before making any information public.


Thank you for helping keep the DorkEye community safe!

There aren’t any published security advisories