Skip to content

Security

Reporting a security problem

If you have found something, this is where to send it. Reports are welcome, taken seriously, and answered by a person.

How to report

Email support@clipkoala.com with a description of the issue, the steps to reproduce it, and what an attacker could actually achieve. Please do not open a public post about it before it is fixed.

You should get a human reply within a few days. ClipKoala is a small project without a bug bounty budget, so there is no payment on offer, and saying that up front is more useful than implying otherwise. Credit in the changelog is offered to anyone who wants it.

In scope

  • clipkoala.com and everything served from it
  • The download, proxy, ZIP, and YouTube API routes
  • The Chrome and Edge browser extension

Out of scope

  • The upstream platforms themselves, and the third-party resolvers ClipKoala calls. Report those to their owners.
  • Reports generated purely by an automated scanner, with no demonstrated impact.
  • Missing security headers or a weak cipher suite with no exploitable consequence.
  • Denial of service, traffic floods, and physical or social engineering attacks.
  • Anything requiring a compromised device or a person to be tricked into a long chain of unlikely actions.

Please test responsibly

Use your own links and your own data. Do not run automated scans that degrade the service for other people, do not attempt to access anyone else's information, and stop as soon as you have demonstrated the issue. Testing within those limits is welcome and will not be treated as an attack.

What the service holds

Worth knowing before you look: ClipKoala has no user accounts, no password database, and no stored files. Links are resolved and discarded, media streams through and is never written to disk, and your history, favourites, and preferences live in your own browser's storage rather than on a server. The most valuable thing an attacker could reach here is the service itself, not a store of user data, because there is not one.

Last reviewed . This policy is also published at /.well-known/security.txt.