Early access — the directory is still filling out, and every rating here is a reported experience.

Blog

The whole map, not just the potholes

by Maliq Barnard · Aug 3, 2026

Let's start by giving credit where it's due. Sites like bugbountyscam.com exist because they surfaced a real, ugly problem: researchers get ghosted after triage, watch valid findings closed as duplicates, get lowballed, and see their bugs silently patched with no credit — and for years they had nowhere to warn each other. That frustration is legitimate. Naming it out loud mattered.

But a complaint wall is only half the map. It tells you where not to go. It never tells you where to go. And that second half is the one that actually changes how a researcher spends their week.

Think about how you really decide where to hunt. You don't just avoid the bad programs — you seek out the good ones: the team that triages in a day, pays the advertised range, credits you properly, and treats a valid report like a gift instead of a threat. Those programs exist, and they're wildly underappreciated, because nobody built a place to say so. A site organized entirely around outrage — a site literally named "scam" — structurally can't be that place. Its incentives point one direction. It can catalog the potholes; it can't draw the roads.

So here's where BugRater stands.

Balanced by design. We collect the good experiences as loudly as the bad ones. A five-star "they were fast, fair, and paid above range" review is worth as much to the community as any horror story — arguably more, because it's actionable. Both, side by side, are what makes a rating trustworthy.

Standardized, so it's comparable. Every review goes through the same structured form: time to first response, payout fairness, whether they paid the advertised range, would-submit-again, and honest practice tags. That's how a grade means the same thing across Apple and a 20-person startup. Vibes don't aggregate; standardized data does.

Researcher-run and moderated. Reviews come from people who actually filed the reports — not vendors talking about themselves, not anonymous drive-bys. Everything is moderated before it publishes, and researchers can verify their platform accounts so their reputation is portable and their voice carries weight.

Accountable in both directions. Programs can claim their profile and respond on the record. We're not interested in a one-sided pile-on; we're interested in a market that's legible to everyone in it. Ratings are reported experiences, not verdicts — and companies get a fair shot to answer.

Data, in the open. The numbers you see on our State of Bug Bounty page aren't marketing. They're aggregated from real researcher reviews — no vendor self-reporting. Over time, that dataset becomes the honest reference the industry has never had: which programs are actually worth your time, backed by evidence.

We're not here to dunk on programs, and we're not here to replace one bias with another. We're here to make the whole picture visible — the fast and fair alongside the slow and hostile — so that ten thousand hours of collective researcher experience stops living in scattered DMs and starts working for everyone.

If you've worked a program, tell us how it went. The good, the bad, the specific. The more of us who do, the sharper the map gets — and the harder it becomes for a bad program to hide, or a great one to go unnoticed.

That's the stance. Now help us draw the roads.

← All posts