Website security

Check the standard vulnerability-reporting contact file.

Look for /.well-known/security.txt, published Contact fields and expiry metadata over HTTPS.

What to review

Read the finding in context.

Contact

Tell researchers where to report

A security.txt Contact field gives good-faith vulnerability reporters a standardized route instead of making them guess.

Expires

Keep the file current

An Expires field helps distinguish maintained security contact information from abandoned metadata.

HTTPS

Use the well-known HTTPS location

The checker looks at the HTTPS /.well-known/security.txt location rather than trusting arbitrary copies elsewhere.

Policy

Optional supporting fields

Canonical, Policy, Encryption, Acknowledgments and language information can provide useful reporting context when appropriate.