Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher profile

RA
Rathore
@Vansh_Rathore · member since August 2026
Contributor Early member
BugScore
not set
Unrated

Not enough independently verifiable evidence yet. This is not a low score, it is no score.

Contribution
19/100

What you’ve added here: reviews written, and how useful others found them.

How this BugScore is built
Platform standing 0/40
No verified HackerOne profile is linked, so there is no platform signal to read. This is the most defensible input we have. Link and verify HackerOne to earn it.
HackerOne signal percentile 0/20
HackerOne has not published a signal percentile for your account, so this earns nothing yet.
HackerOne impact percentile 0/12
HackerOne has not published an impact percentile for your account, so this earns nothing yet.
HackerOne reputation 0/8
HackerOne shows no reputation figure for your account yet.
Vendor-confirmed credit 0/30
No vendor has publicly confirmed your work yet. A verified CVE credit, acknowledgement, or HackerOne thanks counts here, and you can add a CVE from any vendor yourself.
Moderator-verified evidence 0/20
You have no moderator-verified private evidence. Private, NDA’d, or direct-to-vendor work can be verified here without going public.
Verification breadth 0/10
You haven’t verified a platform account yet.
Penalties 0-10
No HackerOne warnings and no upheld disputes count against you.

BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. You’re Unrated because nothing costly-to-fake is linked yet. Not a low score, just nothing to grade. Private and pseudonymous work counts: link a platform, claim a credit, or submit evidence.

How this Contribution is built
Reviews written 8/40
You’ve written 2 program reviews.
Helpful votes received 4/25
Other members marked your reviews helpful 4 times.
Programs covered 6/15
You’ve reviewed 2 distinct programs.
Balanced reviewing 0/10
Post both positive and critical reviews to show you call it as you see it.
Tenure 1/10
You’ve been a member for 1 month.

Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.

No verified platform accounts yet.
2
Reviews written
2
Programs reviewed
2
Reports represented
4
Helpful votes
How they review
4.5 avg rating given
2 positive 0 mixed 0 negative
Where they hunt
1
Bugcrowd 1

Programs reviewed

2

Reviews

National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
Securing the Cosmos: Earning Hall of Fame with NASA
positive

Reporting to the NASA Vulnerability Disclosure Program on Bugcrowd is an incredibly rewarding experience. The security team is highly professional, and they genuinely value the efforts of the community in keeping their massive infrastructure secure. Receiving Hall of Fame recognition and a Letter of Appreciation from NASA is a fantastic milestone for any security researcher. When tackling a scope as vast as NASA's, you don't need to rely on noisy automated scanners. My biggest piece of advice for this program is to master Google Dorking. Advanced dorking is arguably the most powerful technique you can use here. It allows you to sift through the noise, map out forgotten assets, and identify edge cases or misconfigurations that standard tooling completely misses. If you take the time to refine your search parameters and manually investigate the architecture, you can uncover high-impact issues. I would highly recommend this program to anyone looking to make a meaningful impact and test their manual recon skills!

via Bugcrowd reports 1 1st reply Within 3 days resubmit yes recommends yes skill Intermediate
Rathore · Aug 11, 2026 · Share ↗ 2 helpful
Apple Security Bounty
Authentication Bypass on *.apple.com
positive

Hunting on Apple requires patience, but verifying a successful fix makes the wait worthwhile. I reported a vulnerability on *.apple.com where a advance client-side response manipulation allowed a complete bypass of the authentication gate. Tracking the status took some proactive follow-up. While their initial response times can feel sluggish compared to standard bug bounty platforms, the Apple Security Team was professional once communication opened up regarding the remediation and potential bounty rewards. The highlight was working through the remediation phase and actively verifying the fix once they patched the flaw. For other researchers targeting Apple: rely heavily on manual testing and business logic over automated scanners, document your reproduction steps flawlessly, and don't be afraid to politely ping them for updates while you wait.

reports 1 1st reply 1–3 months resubmit yes recommends yes skill Intermediate
Rathore · Aug 8, 2026 · Share ↗ 2 helpful