Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Automattic
Automattic HackerOne
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Automattic? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.

What it pays, by severity

Critical $1,000 avg 51 reports firm
High $347 avg 183 reports firm
Medium $182 avg 429 reports firm
Low $89 avg 534 reports firm

$260,000 paid to researchers in total, $25,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
1,028
in 90 days
Resolved
not published
all time, last one today
Participants
891
hunters engaged
Response efficiency
54%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 18 days 891–1,028
25 Aug 1,028 reports 24 Sep

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
30 days
Resolution
90 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 36 days (22 snapshots): intake up 329 reports; response efficiency down 12 points; 90-day payout up $10,000.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

922 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 foobar7 3,460 129 / 140 92%
2 rafiem 3,303 160 / 211 76%
3 bugra 748 24 / 33 73%
4 reactors08 705 30 / 34 88%
5 cliantech 593 24 / 34 71%
6 xavlimsg 476 37 / 62 60%
7 muhammaddaffa 451 18 / 31 58%
8 hundredpercent 416 18 / 23 78%
9 jaypatel 384 17 / 34 50%
10 fuzzme 382 16 / 17 94%
10 ysx 230 8 / 15 53%
11 mikemyers 360 10 / 10 100%
12 harisec 345 15 / 16 94%
13 suhas_gaikwad 343 13 / 14 93%
14 kurama 318 14 / 47 30%
15 vortfu 315 22 / 24 92%
15 b258ea62bf297b02afa9854 170 5 / 6 83%
16 larbjb 289 13 / 16 81%
17 karimeo 281 8 / 8 100%
18 amosec 261 9 / 9 100%
19 superpan 248 8 / 10 80%
20 kacperszurek 243 12 / 13 92%
21 riadalrashed 238 9 / 17 53%
22 yusuf_furkan 234 13 / 25 52%
23 mazengamal 226 10 / 17 59%

Showing the top 25 of 922 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.

WordPress.com, WooCommerce, WordPress VIP, Jetpack, Beeper, Texts, Akismet, Gravatar, Crowdsignal, Tumblr and more!

Responsiveness
53% HackerOne’s figure
Swag
Offered
Currency
USD
Submissions
Open
Launched
Apr 2014
Scope entries
45 HackerOne’s count

Scope

44 assets
AssetTypeEligibilityMax severity
*.srvcs.tumblr.com WILDCARD ✓ bounty Critical
*.tumblr.com WILDCARD ✓ bounty Critical
akismet.com URL ✓ bounty Critical
api.tumblr.com URL ✓ bounty Critical
assets.tumblr.com URL ✓ bounty Critical
Show all 44 assets
AssetTypeEligibilityMax severity
Beeper OTHER ✓ bounty High
clay.earth URL ✓ bounty High
com.clay.ios APPLE STORE APP ID ✓ bounty High
com.tumblr GOOGLE PLAY APP ID ✓ bounty High
com.tumblr.tumblr APPLE STORE APP ID ✓ bounty High
Crowdsignal OTHER ✓ bounty Critical
embed.tumblr.com URL ✓ bounty Critical
gravatar.com URL ✓ bounty High
intensedebate.com URL ✓ bounty Medium
Jetpack SOURCE CODE ✓ bounty Critical
mailpoet.com URL ✓ bounty Critical
my.pressable.com URL ✓ bounty Critical
parse.ly URL ✓ bounty Critical
safe.tumblr.com URL ✓ bounty Critical
secure.tumblr.com URL ✓ bounty Critical
simperium.com URL ✓ bounty High
simplenote.com URL ✓ bounty High
t.umblr.com URL ✓ bounty Critical
Texts OTHER ✓ bounty High
WooCommerce OTHER ✓ bounty Critical
WordPress Plugins & Themes OTHER ✓ bounty Critical
WordPress VIP OTHER ✓ bounty Critical
wordpress.com URL ✓ bounty Critical
WordPress.com VIP OTHER ✓ bounty Critical
WP Cloud OTHER ✓ bounty Critical
wpscan.com URL ✓ bounty High
www.tumblr.com URL ✓ bounty Critical
*.crowdsignal.net WILDCARD out None
*.poll.fm WILDCARD out None
*.survey.fm WILDCARD out None
*.txmblr.com WILDCARD out None
*/xmlrpc.php OTHER out None
afterthedeadline.com,*.afterthedeadline.com WILDCARD out None
atavist.com URL out None
happy.tools URL out None
learnboost.com,*.learnboost.com URL out None
polishmywriting.com,*.polishmywriting.com WILDCARD out None
scrollkit.com,*.scrollkit.com WILDCARD out None
try.pressable.com URL out None

HackerOne lists 45 scope entries; its public listing groups many assets under one label, so identical entries are shown once.