Early access: the directory is still filling out, and every rating here is a reported experience.

Attack surface intelligence

See which programs are heating up before the crowd does.

BugRater reads the whole bug bounty field as a live market: which programs are heating up as reports pour in, which are under-hunted while intake is still healthy, and what their surface is exposing right now. Stop guessing where to spend the night.

Where to hunt tonight live
1 KAYAK ↑ +26% 1.3/day under-hunted · 249
2 Flutter UK&I ↑ +24% 3.1/day busy · 506
3 Stripe ↑ +22% 8.0/day under-hunted · 339
4 Klarna ↑ +20% 3.9/day under-hunted · 99
5 Dynatrace ↑ +11% 3.9/day under-hunted · 350
153 rated · board, drill-downs, API, digests Open the board →

Signal intelligence

See what's exposed right now

We enumerate each program's surface and flag what deserves a second look. Not findings, leads: the exposed thing worth the first hour of your night.

The signal feed →
17,926

Exposed configs and secrets

Config files, env dumps, and keys reachable on the live surface.

502

Staging and pre-prod high

The softer builds behind a program, where controls slip.

132

Login and admin panels

Auth surfaces and consoles worth a closer look.

2,114

Live-probed hosts

Across 3,049 subdomains enumerated so far.

Freshest exposures

Exposed config 89.••••••• Semmle 🔒
Exposed config 82.••••••• Hilton 🔒
Exposed config 62.••••••• Hilton 🔒
Exposed config 121.••••••• Hilton 🔒
Exposed config 82.••••••• Hilton 🔒
Exposed config 89.••••••• Semmle 🔒

Hosts unlock with a subscription. See what's inside →

Three ways in

However you hunt, the intel meets you there

Pricing →

The board

Scan it in your browser

The full rated board, every program's drill-down, and the live exposure feed. Where to hunt tonight, no setup.

Open the board →

The API

Pull it into your recon

Ten endpoints, metered by the call, with $200 of usage included every month. Wire the intel into your own tooling.

Read the API docs →

Daily digests

Wake up to your shortlist

A quiz picks your programs and the asset types you care about, then a personalized brief lands each morning. Preferences rolling out.

Included · see the offer →

The public record

Your name is already in the file

Every vendor security release names the researchers behind it. We index every line, CVEs and the recognitions that carry no CVE at all, with an identifier you can quote.

Search the record →
Security release credits as of 3 Oct 2026 indexing
CVE-2026-103628 WebGL Google Google Chrome
CVE-2026-103626 FileSystem Google Google Chrome
CVE-2026-103621 Compositing Google Google Chrome
CVE-2026-103630 FedCM xinyang Google Chrome
CVE-2026-103625 V8 Google Google Chrome
CVE-2026-103624 Contextual Tasks xuanocto1221 Google Chrome
CVE-2026-103629 Skia Google Google Chrome
CVE-2026-103622 SVG xinyang Google Chrome
CVE-2026-103623 MediaStream xinyang Google Chrome
CVE-2026-103631 WebRTC Xinyang Ge (Anthropic) Google Chrome
CVE-2026-103631 WebRTC assisted by Claude Google Chrome
CVE-2026-103627 SVG Google Google Chrome
CVE-2026-102331 ANGLE @mfx Google Chrome
CVE-2026-102317 Mojo Google Google Chrome
CVE-2026-102312 Omnibox jodyritonga Google Chrome
CVE-2026-102313 ANGLE Google Google Chrome
CVE-2026-102299 V8 Andrew Boni Google Chrome
CVE-2026-102306 Bluetooth Google Google Chrome
CVE-2026-102307 Dawn Google Google Chrome
CVE-2026-102323 V8 OpenAI Codex Security (amyb) Google Chrome
CVE-2026-102303 GPU Google Google Chrome
CVE-2026-102311 GPU Google Google Chrome
CVE-2026-102300 WebGPU Arni Hardarson (Neonix Security) Google Chrome
CVE-2026-102326 V8 OpenAI Codex Security (amyb) Google Chrome
15,925credit lines
4,696researchers
3,410carry no CVE
Find your line →

From the people who worked them

What it is actually like to submit there

Every review answers the same questions: how many reports, what was paid, how long the first reply took, whether they would go back. So two programs can be compared instead of merely described.

Equifax-vdp Equifax-vdp · HackerOne ★★☆☆☆

Hacktivity: Equifax-vdp (7 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/equifax Disclosed reports analyzed: 7 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty …”

reports 7 resubmit no
ANAnonymous researcher October 2026
Quora Quora · HackerOne ★★☆☆☆

Hacktivity: Quora (8 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/quora Disclosed reports analyzed: 8 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty da…”

reports 8 resubmit no
ANAnonymous researcher October 2026
CodeIgniter CodeIgniter · HackerOne ★★☆☆☆

Hacktivity: CodeIgniter (4 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/codeigniter Disclosed reports analyzed: 4 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bou…”

reports 4 resubmit no
ANAnonymous researcher October 2026
Reverb.com Reverb.com · HackerOne ★★☆☆☆

Hacktivity: Reverb.com (13 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/reverb Disclosed reports analyzed: 13 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty …”

reports 13 resubmit no
ANAnonymous researcher October 2026
ownCloud ownCloud · HackerOne ★★★☆☆

Hacktivity: ownCloud (94 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/owncloud Disclosed reports analyzed: 94 Bounties: $425 avg, $2,000 range, $4,250 total (10 paid) --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from tr…”

reports 94
ANAnonymous researcher October 2026
Eternal Eternal · HackerOne ★★★★☆

Hacktivity: Eternal (100 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/eternal Disclosed reports analyzed: 100 Bounties: $719 avg, $2,750 range, $30,937 total (43 paid) --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from t…”

reports 100 resubmit yes
ANAnonymous researcher October 2026
Inflection Inflection · HackerOne ★★★☆☆

Hacktivity: Inflection (24 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/inflection Disclosed reports analyzed: 24 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bou…”

reports 24
ANAnonymous researcher October 2026
Unikrn Unikrn · HackerOne ★★★☆☆

Hacktivity: Unikrn (28 disclosed)

“Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/unikrn Disclosed reports analyzed: 28 Bounties: $61 avg, $100 range, $365 total (6 paid) --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage tim…”

reports 28
ANAnonymous researcher October 2026

Where credit is recorded in public

Security releases

When a vendor ships a security release it names the researchers behind it: CVEs and additional recognitions alike. We record every line, CVE or not, with a BugRater ID you can quote. If your name is here, the credit is yours to claim: instantly, and durable on your profile.

Top-rated programs

Full rankings →

New · a native Mac app

Give your agents’ findings a permanent trail.

Research Tracker runs on your Mac. Your agents report findings to it over a local API, and each one is appended to a BugRater project: shared, attributed, append-only. On an encrypted project the content is sealed on your machine before it is sent, so a finding becomes evidence of who established what, without handing us the finding itself.

Download for macOS Version 1.4 · Free · Apple-signed · macOS 14+
Research Tracker showing findings with 'in the log' badges tying each to its BugRater entry

Write one

The things you learned the expensive way

See the form →

Every researcher is carrying a set of rules nobody wrote down for them. This program disputes valid scope. That one downgrades every severity. This one is slow but pays above market and will actually argue the technical detail with you. Each of those was paid for with a month of work, or a report that died, or a duplicate filed six hours late.

Writing it down is what turns a private scar into something the next person reads before they spend the month. And because every review answers the same questions, yours does not sit alone as an anecdote. It moves the program's grade, its median response time, and the strengths and concerns other researchers see first.

Post under your handle or anonymously. Either way it is account-backed, so a review here costs something to write. That is exactly why it is worth reading.

What happens after you post

A moderator reads it For abuse and for anything that identifies a person, not for whether it flatters the program. A company cannot have a review of itself taken down.
The grade moves Your ratings recompute the program's letter grade and its median response time. Verified reviews carry double weight, because a verified account has something to lose.
The details stay anonymous Nothing you report is named in an aggregate until 3 reports from 2 different researchers say the same thing. Below that floor it folds into an unnamed residual.
They get one reply, not a veto If the company has claimed its profile it can answer, published under its own name, underneath yours. That is the whole of what claiming buys.
Rate a program: the actual form
sent
resolved
duplicate
n/a · closed
Triage speed★★★★☆ Communication★★★★★ Payout fairness★★★☆☆ Scope clarity★★★★☆
Engages on the technical detail Credits researchers Downgrades severity Fair on duplicates Assigns CVEs Slow to first response Silently patched, no credit

14 strengths and 14 concerns, the same list on every program. That is what makes them countable rather than quotable.

Write a review Takes about five minutes. Everything but the headline and the review body is optional.

Who builds this

No program pays us to be rated.

That single fact is the whole design. A platform earns its money from the companies it hosts, so the moment a researcher's account of a program is inconvenient, the platform has a customer to keep and you do not. We have no such customer.

This is built by someone who submits reports and waits, who has had a month's work closed informative in an hour, and who has watched a duplicate land six hours ahead of him. Every decision beside this was made by someone who expected to be on the receiving end of it.

Maliq Barnard

Security researcher · builds and maintains BugRater
3 published CVEs · reviews on this site under the same handle →

  • 01

    A company cannot delete a review of itself

    Claiming a profile buys one thing: a reply, published under the company's name, beneath the review it answers. There is no takedown path, and moderators cannot post in a company's voice either.

  • 02

    We do not hold your unpatched findings

    Private report detail is encrypted at rest with a key that is not in the database. A collaboration project goes further: keys are generated in your browser and we hold ciphertext we have no way to open. Not “will not”: cannot.

  • 03

    Your report cannot be traced back to you through the numbers

    No detail is named in an aggregate until 3 reports from 2 different researchers say it. Below that floor it folds into an unnamed residual, because a statistic of one is a disclosure wearing a percentage sign.

  • 04

    Claiming your own credit does not wait on us

    The vendor printed your name in their own advisory. A moderator standing between you and that adds no truth to it. Only delay. Claims are instant; disputes are the exception we review, not the rule.

The brief

Get the data, not the noise.

Occasional briefs built from real researcher reviews: which programs are worth your time, what the numbers say, and the pieces we publish. No spam.