We take the security of qrfrog seriously and are grateful for the work security researchers do to keep the internet safer. This page explains how to report vulnerabilities to us responsibly.
1. Scope
Please report security issues that affect qrfrog services and assets operated under the qrfrog.co domain. This includes:
- The qrfrog website, QR generator, dashboard, and API.
- qrfrog.co short links and hosted QR destinations.
- Authentication, billing, analytics, and administrative flows.
2. How to Report
Email: security@qrfrog.co
Please include a clear description of the issue, the affected URL or endpoint, steps to reproduce, and the potential impact. Attach proof-of-concept details, logs, or screenshots if they help us understand the issue.
3. Safe-Harbor Rules
- Do not exploit a vulnerability beyond what is needed to confirm it.
- Do not access, modify, download, or destroy other users' data.
- Do not attack our infrastructure, launch denial-of-service attacks, or use brute force.
- Do not publicly disclose a vulnerability before we have had a reasonable time to fix it.
4. What to Expect
- We acknowledge receipt within 72 hours.
- We investigate and provide an initial assessment within 7 days.
- We work with you to coordinate a fix and agree on a disclosure timeline.
5. Rewards and Recognition
We do not operate a formal bug-bounty program. At our discretion, we may offer account credits, swag, or public thanks for significant, responsibly disclosed reports. We will never ask for payment to process a report.
6. Abuse Reports
If you need to report malicious content or behavior rather than a technical vulnerability, please use the Abuse Contact page or email abuse@qrfrog.co.