Best practice
security.txt
Give researchers a way in.
What it is
A file at /.well-known/security.txt (RFC 9116) that lists how to report a vulnerability to you.
Why it matters
Turns a found bug into a responsible disclosure instead of a public dump or a sale.
Risk without it
Not a vulnerability itself, but its absence means researchers may not know how (or bother) to reach you.
Recommended
Publish Contact and Expires fields; keep Expires in the future.
Set it
Contact: mailto:security@example.com Expires: 2027-01-01T00:00:00.000Z Preferred-Languages: en, pt Canonical: https://example.com/.well-known/security.txt