Security policy
Updated 29 September 2026Reporting a vulnerability
How to report
Send the report to security@unfckd.dev. Please include enough detail that we can reproduce the problem.
- What the issue is and what an attacker could do with it
- The version of unfckd-lite, or the page on unfckd.dev
- Steps to reproduce it, ideally a minimal case
- Your platform and any relevant configuration
- Whether you want credit, and the name to use
You can also report privately through GitHub security advisories at https://github.com/unfckd/unfckd-lite, which keeps the report confidential until a fix ships.
Please do not open a public GitHub issue, post it in the Discord, or publish it anywhere until we have had a chance to fix it.
What you can expect from us
- An acknowledgement within 3 working days
- An assessment and our view of severity within 10 working days
- Progress updates at least every 2 weeks while we work on it
- Credit in the release notes when the fix ships, unless you would rather stay anonymous
This is a small project run by one person, so please read those as honest intentions rather than a contractual service level. If a deadline slips you will hear why.
Disclosure
We aim to ship a fix within 90 days of a valid report. Once a fix is released we will publish an advisory describing the problem and crediting you. If you plan to publish your own write up, we would appreciate you waiting until the fix is out, and we will tell you as soon as it is.
If a vulnerability is already being exploited, tell us that in the first message. We will treat it as urgent and move faster.
In scope
- The unfckd-lite source and released binaries
- The unfckd.dev website
- Our build and release pipeline, including anything that could let someone tamper with a release
Out of scope
The following are unlikely to be treated as vulnerabilities.
- Missing security headers with no demonstrated impact
- Reports produced by an automated scanner with no working proof of concept
- Denial of service through sheer volume of traffic
- Social engineering of the maintainer or of community members
- Anything requiring physical access to a machine, or an already compromised machine
- Issues in GitHub, Discord, or Vercel themselves, which belong to those vendors
- Vulnerabilities in FiveM, RedM, or third-party resources, which belong to their authors
Testing safely
Test against your own installation. unfckd-lite runs locally, so you can test it freely on hardware you control. If you need to test something against unfckd.dev itself, keep it to a volume that could not affect anyone else, and stop as soon as you have confirmed the finding.
Do not access data belonging to other people, do not degrade the service, and do not run destructive tests against our infrastructure.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, and we will not report you to the authorities, for testing conducted within these rules.
This promise is ours alone to make. It cannot bind Vercel, GitHub, Discord, or anyone else whose systems you might touch, and it does not override Dutch criminal law. Stay within the scope above and this will not come up.
Rewards
We run no bug bounty and we have no budget for one. This is a free project. What we can offer is a fast response, a credited advisory, and genuine thanks.
Machine readable version
A security.txt file is published at the standard location, following RFC 9116.
Related documents
- Acceptable use policy, which covers what is not allowed on our infrastructure
- Privacy policy, which covers what we do with data
