responsible disclosure / bug bounty

No Financial Reward

As a small company, Westbury Digital isn't in a position to offer financial remuneration. However, I genuinely welcome responsible disclosure and value the effort that goes into finding real issues.

What's In Scope

Genuine, exploitable vulnerabilities with a demonstrable attack path. Examples: XSS with real impact, authentication or authorisation bypasses, SQL injection, sensitive data exposure, or similar issues where you can show meaningful harm.

What's Out of Scope

The following will not be accepted or acknowledged:

  • Outdated library versions — a CVE against a library (e.g. jQuery) is not a finding unless you can demonstrate that a vulnerable function is actually being invoked and exploitable in this specific context.
  • Rate limiting — do not test, probe, or report rate limiting on any endpoint.
  • Data alteration or deletion — any attempt to modify, corrupt, or delete data is outside scope and unwelcome.
  • Automated scanner output — raw results from Nikto, Burp passive scan, or similar tools with no manual verification or demonstrated impact.
  • Missing security headers without demonstrated impact — e.g. absence of a clickjacking header on a site with no login functionality.
  • Email configuration — SPF, DKIM, DMARC, MTA-STS, and related DNS findings.
  • Denial of service — do not flood, load test, or otherwise attempt to degrade the servers.

Latest from the blog

The padlock lies (a little)

Setting up SSL on my home network led to an uncomfortable realisation: the padlock shows you where encryption starts, not where it ends. That distinction matters more than most people think

2026-05-15

Read post →

Notoriety Board

A place on the board. Any verified, in-scope finding gets your name or handle listed here with the vulnerability and its potential impact.

7
Received
2
Accepted
5
Closed
29%
Acceptance Rate
CVSS Name / Handle Vulnerability Potential Impact
3.5 Alan Jose Host Header Injection Crash Online Store
6.1 [CVE-2022-38796] Nilesh Agrawal Koyo Prototype Pollution Attack Serverside misdirection if incorrectly referenced

What's CVSS? An open industry standard for scoring vulnerability severity from 1–10.

Disclose Here

Use the submission form to report a finding. You'll receive a tracking ID so you can check the status of your submission.

Submit a Finding

Already submitted? Track your submission with your ID.