Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Alibaba BBP
Alibaba BBP HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Alibaba BBP? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical amount not published 2 reports
High amount not published 7 reports
Medium amount not published 56 reports
Low amount not published 23 reports

$230,625 paid to researchers in total. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
0
in 90 days
Resolved
320
all time, last one 3 years ago
Participants
514
hunters engaged
Response efficiency
not published
HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 0–0
25 Aug 0 reports 22 Sep

Response targets it sets itself

First response
1 day
Triage
2 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

submissions paused

Over 31 days (17 snapshots): no change on the figures worth watching.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

531 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 alessandro_ 793 18 / 25 72%
2 godiego 747 0 / 22 0%
3 krizzsk 737 14 / 17 82%
4 dozybrit 710 9 / 12 75%
5 badf00d 594 0 / 1 0%
6 ola0 528 0 / 1 0%
7 sergeym 418 3 / 7 43%
8 harisec 381 5 / 6 83%
9 ashrafabdelrazik 354 2 / 14 14%
10 melbadry9 351 11 / 14 79%
11 neelponkia123 348 8 / 18 44%
12 uttam_10 322 14 / 17 82%
13 avishai 286 0 / 0
13 wunderwuzzi23 286 0 / 1 0%
15 todayisnew 282 3 / 9 33%
16 mghack123 279 6 / 7 86%
17 jp_seg 274 0 / 1 0%
18 ssharmaz 269 0 / 2 0%
19 rafsanzami 267 11 / 15 73%
20 reactivity 264 5 / 6 83%
21 umvs 240 2 / 10 20%
22 p4fg 227 4 / 11 36%
23 gamer7112 225 7 / 8 88%
24 k1ra_ 220 0 / 2 0%
25 tvmpt 198 0 / 2 0%

Showing the top 25 of 531 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 17 Sep 2026.

Swag
Offered
Currency
USD
Submissions
Paused
Launched
Apr 2020
Scope entries
16 HackerOne’s count

Scope

16 assets
AssetTypeEligibilityMax severity
*.1688.com WILDCARD ✓ bounty Medium
*.alibaba-inc.com WILDCARD ✓ bounty Critical
*.alibaba.com WILDCARD ✓ bounty Critical
*.alibabacloud.com WILDCARD ✓ bounty Critical
*.aliexpress.com WILDCARD ✓ bounty Critical
Show all 16 assets
AssetTypeEligibilityMax severity
*.aliexpress.ru WILDCARD ✓ bounty Critical
*.alimama.com WILDCARD ✓ bounty Critical
*.aliyun-inc.com WILDCARD ✓ bounty Critical
*.aliyun.com WILDCARD ✓ bounty Critical
*.cainiao.com WILDCARD ✓ bounty Critical
*.Daraz.com WILDCARD ✓ bounty Critical
*.dingtalk.com WILDCARD ✓ bounty Critical
*.lazada.* WILDCARD ✓ bounty Critical
*.taobao.com WILDCARD ✓ bounty Critical
*.tmall.com WILDCARD ✓ bounty Critical
www.alibabagroup.com URL ✓ bounty Critical