Skip to content

Security: EvilmaxSec/TheWatcher

Security

SECURITY.md

Reporting a Vulnerability

⚠️ DO NOT CREATE PUBLIC ISSUES FOR SECURITY VULNERABILITIES ⚠️

Instead, please follow responsible disclosure:

  1. Email: evilmaxsec@proton.me
  2. PGP Key: Available on request
  3. Expected Response: Within 48 hours

What to Include

  • Detailed description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Responsible Disclosure Policy

We take security seriously and will:

  1. Acknowledge receipt within 48 hours
  2. Investigate and validate the issue
  3. Develop and release a fix
  4. Credit the reporter (if desired)

Scope

This policy applies to vulnerabilities found in:

  • TheWatcher source code
  • PHP server implementation
  • Template security

Out of Scope

  • Social engineering aspects (this is intentional for training)
  • Browser permission prompts (standard browser behavior

There aren't any published security advisories