Security
vulns.co publishes defensive knowledge and controlled probes for authorized security testing.
Site design
- Strict Content Security Policy and framing restrictions.
- Static public content with a read-only hosted MCP server.
- Browser-local utilities and local paste-analysis tools. No credential collection.
- Daily public threat-intelligence refreshes isolated from user input.
Responsible disclosure
If you discover a vulnerability in vulns.co itself, stop at the minimum proof, do not access other users' data, and contact GKData.io with reproducible evidence.
Authorized use
Payloads and commands are for systems you own or are explicitly authorized to test. Respect program scope, rate limits, and data-handling rules.