Responsible reporting
Email security@foopixel.com before sharing a vulnerability publicly. Include the affected URL or component, a concise description, reproduction steps, impact, and any safe evidence that helps us validate the issue.
Please avoid accessing, changing, or retaining another person's content; stop testing once you have enough evidence; and do not run load tests, phishing, destructive actions, or tests involving real credentials or personal data. Never include passwords, API keys, or suspected abusive imagery in a report.
Good-faith safe harbor intent
We intend to work with researchers who make a good-faith effort to follow this guidance. We will consider that cooperation when reviewing a report, while reserving the need to protect users, comply with law, and investigate serious harm. This is an expression of intent, not a formal bounty program, contract, immunity, or guarantee.
Review and response
We assess reports and may ask questions or take appropriate action. We do not promise a response time, bounty, public credit, or particular remediation outcome. Please do not publish details while a material risk remains open.
Current service boundary
FooPixel is a FooPlugins service. See our Privacy Notice for information about how service data is handled, or use the abuse page for content and rights concerns.
For general questions, contact hello@foopixel.com. For an image or rights report, use abuse@foopixel.com.