Powered by: Allows bounty splitting:
Average time to first program response: 37
Average time to bounty awarded null: 338
Average time to report resolved: 361
Handle matomo
Managed program: false
Name: Matomo
Offers bounties: true
Offers swag: true
Response efficiency percentage: 91
Submission state: open
Url: https://hackerone.com/matomo
Website: https://matomo.org
In scope: Asset identifier: 737216887Asset type: APPLE_STORE_APP_IDAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: Eligible for submissions: trueInstruction: Matomo Mobile 2 iOS App
Only critical issues compromising the token are in scope.Integrity requirements: lowMax severity: mediumAsset identifier: https://github.com/innocraft/Asset type: SOURCE_CODEAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: All other software on the innocraft GitHub organisationIntegrity requirements: lowMax severity: highAsset identifier: https://github.com/matomo-orgAsset type: SOURCE_CODEAvailability requirement: lowConfidentiality requirement: mediumEligible for bounty: trueEligible for submissions: trueInstruction: All other software on the matomo-org GitHub organisationIntegrity requirements: lowMax severity: highAsset identifier: https://github.com/matomo-org/matomoAsset type: SOURCE_CODEAvailability requirement: Confidentiality requirement: Eligible for bounty: trueEligible for submissions: trueInstruction: this repository contains the source code of Matomo AnalyticsIntegrity requirements: Max severity: criticalAsset identifier: https://matomo.cloud/Asset type: URLAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Matomo Analytics Cloud
*$username.matomo.cloud* is also in scope, but please limit tests to ones that don't affect the live instance. (no automated tools) You can easily set up your own Matomo instance for extensive testing (see https://matomo.org/docs/installation/) Integrity requirements: highMax severity: criticalAsset identifier: https://plugins.matomo.org/developer/innocraftAsset type: SOURCE_CODEAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Official plugins by InnocraftIntegrity requirements: highMax severity: criticalAsset identifier: https://plugins.matomo.org/developer/matomo-orgAsset type: SOURCE_CODEAvailability requirement: highConfidentiality requirement: highEligible for bounty: trueEligible for submissions: trueInstruction: Official plugins by the Matomo teamIntegrity requirements: highMax severity: criticalAsset identifier: org.piwik.mobile2Asset type: GOOGLE_PLAY_APP_IDAvailability requirement: lowConfidentiality requirement: lowEligible for bounty: Eligible for submissions: trueInstruction: Matomo Mobile 2 Android App
Only critical issues compromising the token are in scope.Integrity requirements: lowMax severity: medium