Security
Found a vulnerability? Here's how to tell us, what's in scope, and what you get for a good report — credit and a thank-you, not a cash bounty.
Version 2026-09-24
Report a vulnerability
If you find a security issue on nehruplaceonline.com, tell us before you tell anyone else, and give us a reasonable chance to fix it before you publish anything about it. In return we will not pursue legal action over good-faith research that follows the rules below.
Report through the contact page, or the machine-readable contact in /.well-known/security.txt. Include what you found, the steps to reproduce it, and what you think the impact is — a working reproduction is worth more to us than a severity guess.
What's in scope
nehruplaceonline.com itself: authentication, authorisation between accounts (a dealer reading another dealer's data, for instance), the payment and credit-ledger flow, and anything that lets stored data be read, changed or deleted without the right to do so.
What's out of scope
Reports that only prove a user can be tricked into hurting themselves (self-XSS, clickjacking with no realistic exploit, or a missing rate limit on an endpoint that costs the account holder nothing to abuse), volumetric attacks of any kind, social engineering of staff or dealers, and physical access to Nehru Place premises.
A missing security header or a low-severity information disclosure (a stack trace, a verbose error) is welcome as a report but is unlikely to be credited on its own — tell us anyway; it still gets fixed.
What you get
Credit on this page, by the name you tell us to use, once the fix has shipped — we do not name a reporter before that. And a real thank-you: we will tell you what the fix was and when it went out.
No cash reward. This is a directory, not a company with a bounty budget, and saying so here is more honest than a program that promises a payout and then argues about severity when the report comes in.
Researchers credited
Nobody yet — this page is new. Be the first.
Questions about any of this go through the contact page.