Early access: this site has moved to bugrater.com.
NR Unrated
PortSwigger Web Security
3 more reviews needed for a grade
Write a review Claim this company profile

Work at PortSwigger Web Security? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical no reports on record
High $6,000 avg 9 reports indicative
Medium $1,500 avg 19 reports indicative
Low $300 avg 56 reports firm

$91,900 paid to researchers in total, $13,800 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
73
in 90 days
Resolved
115
all time, last one 17 days ago
Participants
114
hunters engaged
Response efficiency
99%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 68–76
27 Aug 73 reports 24 Sep

Response targets it sets itself

First response
1 day
Triage
2 days
Bounty
30 days
Resolution
90 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 33 days (18 snapshots): intake up 7 reports; response efficiency down 1 points; 90-day payout up $3,300.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

110 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 abr1k0s 239 18 / 20 90%
2 issuefinder 168 4 / 4 100%
3 h13- 111 3 / 3 100%
3 fuckthisnoise 22 1 / 3 33%
4 osama-hamad 66 3 / 7 43%
5 0ertxta 57 1 / 1 100%
5 0xd0m7 57 1 / 1 100%
5 boomerang_ 57 1 / 1 100%
5 duesee 57 1 / 1 100%
5 intrd 57 1 / 1 100%
5 jlleitschuh 57 1 / 2 50%
5 kawakatz 57 1 / 2 50%
5 mattaustin 57 1 / 1 100%
5 morisson 57 1 / 1 100%
5 ne555t 57 1 / 1 100%
5 raw-bin 57 1 / 1 100%
5 warringaa 57 1 / 1 100%
17 an1msh 54 0 / 0
17 bobblybear 54 2 / 2 100%
17 dwbzn 54 0 / 0
20 arielrachamim 32 0 / 0
20 coolninja 32 1 / 1 100%
20 crelic_ 32 0 / 0
20 harisec 32 1 / 1 100%
20 joaxcar 32 1 / 1 100%

Showing the top 25 of 110 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

Burp Suite is the leading software for web security testing

Responsiveness
99% HackerOne’s figure
Swag
Offered
Currency
USD
Submissions
Open
Launched
Nov 2016
Scope entries
16 HackerOne’s count

Scope

16 assets
AssetTypeEligibilityMax severity
ai.portswigger.net URL ✓ bounty Critical
Burp Collaborator DOWNLOADABLE EXECUTABLES ✓ bounty Critical
Burp Suite DAST OTHER ✓ bounty Critical
Burp Suite Enterprise Edition DOWNLOADABLE EXECUTABLES ✓ bounty Critical
Burp Suite Pro/Community DOWNLOADABLE EXECUTABLES ✓ bounty High
Show all 16 assets
AssetTypeEligibilityMax severity
collections.portswigger.net URL ✓ bounty Critical
forum.portswigger.net URL ✓ bounty Critical
http1mustdie.com URL ✓ bounty High
https://enterprise-demo.portswigger.net/ URL ✓ bounty Critical
id.portswigger.net URL ✓ bounty Critical
links.portswigger.net URL ✓ bounty Critical
portswigger.net URL ✓ bounty Critical
share.portswigger.net URL ✓ bounty Critical
*.portswigger.net WILDCARD out None
*.web-security-academy.net WILDCARD out None
Burp Suite Extension (BApps) DOWNLOADABLE EXECUTABLES out None