
Matomo
External Program
Submit bugs directly to this organization
No technology is perfect, and Matomo believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.
The following issues are outside the scope of our rewards program:
token_auth acts as the user's password and is used to authenticate in API requests (see FAQ).*.matomo.org websites.Please submit any open source security issues directly to us via HackerOne, do not open security-related issues on public GitHub repositories.
Thank you for helping keep Matomo and our users safe!