๐ Security & Responsible Disclosure
We care about the security of GhostStat and of everyone who trusts it with their
data. If you've found a vulnerability, thank you โ and please tell us the right
way so we can fix it before anyone gets hurt.
The one rule: report privately, never publicly
Do not open a public thread, gist, or social post about a security issue.
Publishing an unfixed vulnerability puts real users at risk. Instead:
- Email โ security@ghoststat.me with the details.
- If you can, encrypt sensitive details or ask us for a secure channel first.
We aim to acknowledge your report within 3 business days and to keep you
updated as we work through it. (Adjust this window to what you can honestly
commit to.)
What to include
A good report gets fixed faster:
- What the issue is and where โ which subdomain/component
(app ยท api ยท cdn ยท gs ยท counter ยท the forum).
- Steps to reproduce, or a minimal proof-of-concept.
- The impact as you see it (what could an attacker actually do?).
- Your setup โ browser, plan, and anything else relevant.
Scope
In scope: app.ghoststat.me, api.ghoststat.me, cdn.ghoststat.me,
gs.ghoststat.me, counter.ghoststat.me, and the community forum at
discuss.ghoststat.me โ authentication, the eco-identity/SSO flow, the plugin
system, the tracking pipeline, and data access between accounts.
Out of scope (please don't report these as vulnerabilities):
- Volumetric denial-of-service or load testing โ never run these against our
infrastructure.
- Spam, social engineering, or phishing of our team or members.
- Self-XSS, missing "best-practice" headers with no demonstrable impact, or
automated-scanner output without a working proof-of-concept.
- Anything requiring a already-compromised device or a physically stolen session.
Testing rules (please read)
While researching in good faith:
- Only ever use your own accounts and test data. Never access, modify, or
exfiltrate another user's data โ if a flaw would let you, stop and report it;
don't prove it against real people.
- No destructive testing โ don't delete data, degrade the service, or pivot
deeper than needed to demonstrate the issue.
- Don't run automated scanners hard enough to affect availability.
Safe harbour
If you follow this policy โ report privately, stay in scope, act in good faith,
and don't harm users or data โ we will not pursue or support legal action
against you, and we'll work with you openly on a fix and a coordinated
disclosure timeline. Good-faith research makes GhostStat safer, and we treat it
that way.
Recognition
There's no cash bounty (we're a small, independent project), but we don't take
your work for granted:
- With your permission, we'll credit you in the release notes and a security
acknowledgements list.
- A serious, well-documented, responsibly-disclosed finding is exactly the kind
of contribution the Sentinel path in the Ghost Guild recognises โ up to a
free GhostStat Pro account, for life โ The Ghost Guild.
After you report
- We acknowledge and start investigating.
- We confirm the issue and agree a fix + disclosure timeline with you.
- We ship the fix, credit you (if you want), and โ once users are safe โ we're
happy for the details to be shared.
Thank you for helping keep GhostStat, and the people who use it, safe.
โ The GhostStat Team ยท security@ghoststat.me