Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Yelp
Yelp HackerOne
2 more reviews needed for a grade
Write a review Claim this company profile

Work at Yelp? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 4 Oct 2026.

What it pays, by severity

Critical $150 avg 16 reports indicative
High $1,667 avg 42 reports firm
Medium $2,019 avg 114 reports firm
Low $1,250 avg 135 reports firm

$370,000 paid to researchers in total, $40,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
156
in 90 days
Resolved
522
all time, last one 5 days ago
Participants
382
hunters engaged
Response efficiency
44%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 29 days 156–177
5 Sep 156 reports 4 Oct

Response targets it sets itself

First response
2 days
Triage
7 days
Bounty
5 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 45 days (115 snapshots): intake up 6 reports; response efficiency down 14 points; 90-day payout up $20,000.

See how this programme’s report load compares to others →

Reviews

1 published
Hacktivity: Yelp (75 disclosed)
★★★★★ neutral

Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/yelp Disclosed reports analyzed: 75 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty data.

via HackerOne reports 75
Anonymous researcher · Oct 1, 2026 · Share ↗ 0 helpful
0 comments

Log in to comment

Who this program credits

406 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 cliantech 667 27 / 38 71%
2 akkilion 444 16 / 30 53%
3 hk755a 379 12 / 17 71%
3 intrax 379 6 / 31 19%
5 todayisnew 309 7 / 10 70%
6 0xold 251 18 / 19 95%
7 siddiki 248 10 / 20 50%
8 mikemyers 235 4 / 6 67%
8 quistertow 235 9 / 14 64%
10 lil_endian 228 3 / 3 100%
11 nahamsec 226 7 / 12 58%
11 vijaysimha-reddy 226 4 / 8 50%
13 faisalahmed 207 11 / 20 55%
14 k0reph1l 196 5 / 9 56%
15 no-need 192 2 / 8 25%
16 akashc99 184 8 / 15 53%
17 larocas 181 1 / 1 100%
18 fr4via 178 2 / 2 100%
19 detroitsmash 168 4 / 12 33%
20 dhakal_bibek 165 8 / 19 42%
21 mufasalee001 164 3 / 18 17%
22 sergeym 155 7 / 14 50%
23 melar_dev 142 6 / 7 86%
24 asm0d3us 141 5 / 11 45%
25 whitesec121 135 5 / 5 100%

Showing the top 25 of 406 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 30 Sep 2026.

Connecting people to great local businesses in communities around the world.

Responsiveness
44% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Sep 2016
Scope entries
26 HackerOne’s count

Scope

25 assets
AssetTypeEligibilityMax severity
*.yelp.com WILDCARD ✓ bounty Critical
*.yelpwifi.com WILDCARD ✓ bounty Low
284910350 APPLE STORE APP ID ✓ bounty Critical
542767785 APPLE STORE APP ID ✓ bounty Critical
936983378 APPLE STORE APP ID ✓ bounty Critical
Show all 25 assets
AssetTypeEligibilityMax severity
api.yelp.com OTHER ✓ bounty Critical
auto-api.yelp.com URL ✓ bounty Critical
biz-app.yelp.com URL ✓ bounty Critical
biz.yelp.com URL ✓ bounty Critical
com.yelp.android GOOGLE PLAY APP ID ✓ bounty Critical
com.yelp.android.biz GOOGLE PLAY APP ID ✓ bounty Critical
m.yelp.com URL ✓ bounty Critical
mobile-api.yelp.com URL ✓ bounty Critical
restaurants.yelp.com URL ✓ bounty Low
www.yelpreservations.com URL ✓ bounty Critical
yelptop100.com URL ✓ bounty Low
*.yelp-support.com WILDCARD out None
app.yelpwifi.com URL submit only Critical
blog.yelp.com URL out None
cloud.e.yelp-business.com URL out None
engineeringblog.yelp.com URL out None
www.yelp-ir.com URL out None
yelp-press.com URL out None
yelp.careers URL out None
yelp.nowait.com URL submit only Critical

HackerOne lists 26 scope entries; its public listing groups many assets under one label, so identical entries are shown once.