Early access: this site has moved to bugrater.com.
NR Unrated
WordPress
WordPress HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at WordPress? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 23 Sep 2026.

What it pays, by severity

Critical no reports on record
High no reports on record
Medium no reports on record
Low no reports on record

$190,000 paid to researchers in total, $95,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
1,641
in 90 days
Resolved
not published
all time, last one today
Participants
587
hunters engaged
Response efficiency
71%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 28 days 1,239–1,641
25 Aug 1,641 reports 23 Sep

Response targets it sets itself

First response
5 days
Triage
10 days
Bounty
20 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 34 days (31 snapshots): intake up 501 reports; response efficiency up 9 points; 90-day payout up $35,000.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

603 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 rafiem 3,882 202 / 287 70%
2 paulos__ 1,221 65 / 92 71%
3 simonscannell 410 9 / 10 90%
4 hoangkien1020 344 12 / 13 92%
5 skansing 326 13 / 15 87%
6 bornwinnerrr 308 16 / 25 64%
7 buggedout 272 3 / 4 75%
8 p4p3r_hak 267 14 / 39 36%
9 karimeo 259 6 / 6 100%
10 foobar7 205 9 / 10 90%
10 ysx 90 5 / 5 100%
11 yuvraj_dighe 178 9 / 9 100%
12 jakubk 171 15 / 35 43%
13 svennergr 136 3 / 3 100%
14 vvh1te3zz 130 14 / 18 78%
14 argareksapatii 119 7 / 12 58%
15 jdgrimes 113 5 / 6 83%
16 codertom 112 7 / 9 78%
17 evanricafort 108 6 / 17 35%
18 ducnt_ 103 3 / 3 100%
18 kolchylilah 103 7 / 10 70%
20 hanno 98 4 / 5 80%
20 mopman 98 4 / 4 100%
22 mickey_cyberkid 96 5 / 5 100%
22 opnsec 96 2 / 2 100%

Showing the top 25 of 603 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Beautiful sites of any kind.

Responsiveness
69% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Apr 2017
Scope entries
31 HackerOne’s count

Scope

31 assets
AssetTypeEligibilityMax severity
*.buddypress.org,bbpress.org,profiles.wordpress.org WILDCARD ✓ bounty Critical
*.trac.wordpress.org, *.svn.wordpress.org, *.git.wordpress.org, github.com/WordPress SOURCE CODE ✓ bounty Critical
*.wordcamp.org WILDCARD ✓ bounty Critical
*.wordpress.net WILDCARD ✓ bounty Low
*.wordpress.org WILDCARD ✓ bounty Critical
Show all 31 assets
AssetTypeEligibilityMax severity
api.wordpress.org URL ✓ bounty Critical
bbPress Core SOURCE CODE ✓ bounty Critical
BuddyPress Core SOURCE CODE ✓ bounty Critical
codex.wordpress.org,codex.bbpress.org,codex.buddypress.org URL ✓ bounty Medium
doaction.org URL ✓ bounty Critical
GlotPress SOURCE CODE ✓ bounty Critical
Gutenberg SOURCE CODE ✓ bounty Critical
gutenberg.run URL ✓ bounty Low
mercantile.wordpress.org URL ✓ bounty Medium
Official WordPress plugins SOURCE CODE ✓ bounty Critical
planet.wordpress.org URL ✓ bounty Critical
WordPress Core SOURCE CODE ✓ bounty Critical
wordpressfoundation.org URL ✓ bounty Medium
WP-CLI SOURCE CODE ✓ bounty Critical
*.wordpress.com WILDCARD out None
335703880 APPLE STORE APP ID out None
Archived GitHub repositories OTHER out None
Digital Ocean, AWS, etc OTHER out None
https://github.com/wordpress-mobile/ SOURCE CODE out None
https://github.com/wordpress-mobile/WordPress-iOS SOURCE CODE out None
irclogs.wordpress.org URL out None
lists.wordpress.org URL out None
munin-*.wordpress.org WILDCARD out None
org.wordpress.android GOOGLE PLAY APP ID out None
status.wordpress.org,glotpress.blog,wordpress.tv URL out None
wordpress.tv URL out None