Security fixes are applied to the latest version of base31.org on the main branch. Older revisions may not receive security updates.
Please do not open a public issue for a security vulnerability. Email hello@base31.org with:
- A clear description of the issue and its impact
- The affected URL, route, or component
- Steps to reproduce, including a minimal proof of concept when safe
- Any suggested mitigation or relevant logs
You can encrypt sensitive details with our PGP key if requested. Please allow reasonable time for investigation and remediation before public disclosure.
We will acknowledge reports when received, validate the issue, and keep the reporter informed as we work toward a fix. Reports that involve user data, credentials, or active exploitation may be prioritized.
Please avoid accessing, changing, or deleting data that does not belong to you. We ask researchers to stop testing once a vulnerability is confirmed and to keep private any details that could enable exploitation.
This policy covers base31.org and its first-party services. Third-party sites listed in the directory are independently operated and should be reported to their owners.
Thank you for helping keep the open web safer.
Last updated: October 3, 2026
.