Security Policy
Security researchers and users can help protect Wheel Names by reporting suspected vulnerabilities privately and responsibly. This policy explains what information is useful, which testing is out of scope, and what to expect after a report.
Last updated: July 30, 2026
How to report a security issue
Use Contact Us and begin the message with Security Report. Provide a concise description and avoid placing exploit details in public comments, social posts, shared wheels, or screenshots.
What to include
- The affected wheelnames.org URL or feature.
- Browser, device, and whether you were signed in to WordPress.
- Clear reproduction steps and observed impact.
- A minimal proof of concept that does not expose real user data.
- Suggested remediation, if known.
- A safe way to contact you with follow-up questions.
Safe testing boundaries
Use your own data and accounts. Stop testing if you access data that is not yours. Do not conduct denial-of-service tests, destructive actions, spam, social engineering, physical attacks, automated high-volume scans, credential stuffing, or changes to production content. Do not retain or share personal information encountered accidentally.
Common out-of-scope reports
Reports normally need a practical security impact. Automated scanner output without validation, missing cosmetic headers with no exploit, self-XSS, clickjacking on pages with no sensitive action, outdated browser behavior, rate-limit requests that caused no harm, and issues in third-party services may not qualify.
How we handle reports
We prioritize by reproducibility, affected users, data exposure, exploitability, and service impact. We may ask for clarification, coordinate a fix, or explain why a report is out of scope. This policy does not create a promise of payment, employment, public credit, or a specific response deadline.
Security tips for Wheel Names users
Do not enter passwords or sensitive records, keep your browser updated, review shared links before sending them, and delete local site data on shared devices. Important draws should have a separate participant list and result record.
Vulnerability disclosure reference: CISA vulnerability disclosure resources.
