Security operative
Home›Security
◈ GUARDED

Security

Last updated: January 1, 2025

This perimeter is watched. Move your cursor — our operative has you in her sights. Report weaknesses responsibly and we'll fix them fast.

TL;DRFind a bug, email us, don't go public until it's patched. Act in good faith and you're protected.

Report a vulnerability

Found a hole in our defenses? We want to hear it. Email our security contact with clear reproduction steps and any proof-of-concept. We read every report.

  • Email: security@ or [email protected] (see security.txt).
  • Include: affected URL/endpoint, steps to reproduce, impact, and a PoC if possible.
  • Do NOT publicly disclose before we've had a chance to fix it.
  • Do NOT run automated scanners that degrade service for other users.

Scope

In scope for responsible disclosure:

  • animedex.fun and its subdomains.
  • Authentication / session handling (AniList & MAL OAuth flows).
  • Stored or reflected XSS, CSRF, SSRF, injection, and access-control flaws.
  • Anything that exposes another user's data or lets you act as them.

Out of scope: third-party streaming providers we proxy (we don't control them), rate-limit/DoS reports, missing best-practice headers on non-sensitive static assets, and self-XSS.

Disclosure process

Here's what happens after you report:

  • Acknowledgement — we confirm receipt as soon as we can.
  • Triage — we validate and assess severity.
  • Fix — we patch, verify, and deploy.
  • Credit — with your permission, we'll thank you publicly.

How we're hardened

Defenses currently standing guard:

  • HTTPS-only with HSTS (max-age 2 years, includeSubDomains, preload).
  • Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy.
  • Cross-Origin-Opener-Policy and Cross-Origin-Resource-Policy set.
  • User-supplied HTML (profile bios) sanitized with DOMPurify before render.
  • Parameterized database queries — no string-built SQL.
  • AniList tokens stored in httpOnly cookies, inaccessible to JavaScript.
  • Rate limiting and bot filtering on API routes.
  • Provider allowlists on stream proxies to prevent request redirection.

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your actions authorized, will not pursue legal action, and will work with you to understand and resolve the issue quickly. Act in good faith and we've got your back.

Security contact

[email protected]

PGP available on request · see /.well-known/security.txt