Early access: the directory is still filling out, and every rating here is a reported experience.

Researcher profile

AA
aaronamran
@aaronamran · member since August 2026
Contributor Early member
BugScore
not set
Unrated

Not enough independently verifiable evidence yet. This is not a low score, it is no score.

Contribution
9/100

What you’ve added here: reviews written, and how useful others found them.

How this BugScore is built
Platform standing 0/40
No verified HackerOne profile is linked, so there is no platform signal to read. This is the most defensible input we have. Link and verify HackerOne to earn it.
HackerOne signal percentile 0/20
HackerOne has not published a signal percentile for your account, so this earns nothing yet.
HackerOne impact percentile 0/12
HackerOne has not published an impact percentile for your account, so this earns nothing yet.
HackerOne reputation 0/8
HackerOne shows no reputation figure for your account yet.
Vendor-confirmed credit 0/30
No vendor has publicly confirmed your work yet. A verified CVE credit, acknowledgement, or HackerOne thanks counts here, and you can add a CVE from any vendor yourself.
Moderator-verified evidence 0/20
You have no moderator-verified private evidence. Private, NDA’d, or direct-to-vendor work can be verified here without going public.
Verification breadth 0/10
You haven’t verified a platform account yet.
Penalties 0-10
No HackerOne warnings and no upheld disputes count against you.

BugScore weighs signal by how hard it is to fake: HackerOne’s own percentiles, vendor-confirmed credits, and evidence a moderator checked. Writing reviews here does not move it. That is Contribution, below. You’re Unrated because nothing costly-to-fake is linked yet. Not a low score, just nothing to grade. Private and pseudonymous work counts: link a platform, claim a credit, or submit evidence.

How this Contribution is built
Reviews written 4/40
You’ve written 1 program review.
Helpful votes received 1/25
Other members marked your reviews helpful 1 time.
Programs covered 3/15
You’ve reviewed 1 distinct program.
Balanced reviewing 0/10
Post both positive and critical reviews to show you call it as you see it.
Tenure 1/10
You’ve been a member for 1 month.

Contribution measures citizenship on BugRater: reviews, helpful votes, breadth, and tenure. It is cheap to earn by design, and it is kept deliberately separate from BugScore so activity here can never stand in for demonstrated skill.

No verified platform accounts yet.
1
Reviews written
1
Programs reviewed
0
Reports represented
1
Helpful votes
How they review
4.0 avg rating given
1 positive 0 mixed 0 negative
Where they hunt
Bugcrowd 1

Programs reviewed

1

Reviews

National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program
NASA's Highly Competitive VDP on Bugcrowd
positive

NASA VDP is triaged by Bugcrowd team before handing it over to NASA officials for confirmation. I noticed that Bugcrowd's bot such as teapot_bugcrowd tends to mark report submissions as N/A. This was the case with my accepted report that earned me the NASA's LoR. I submitted a report in December 2024, but Bugcrowd's bot triaged it as N/A. Only in June 2025 did Bugcrowd's human triagers receive similar reports from other hackers, and they traced my report to be the first submission of its kind and marked my report as Accepted. The NASA VDP accepts only unique, non-duplicate reports that demonstrate a real security impact. However, my main critique of this program is related to a vulnerability I discovered. My report was closed as a duplicate of one submitted by another hacker over a year ago. Despite this long timeline, the affected endpoint remains completely unpatched, which I believe will cause more hackers to waste time and effort.

via Bugcrowd resubmit yes
aaronamran · Aug 3, 2026 · Share ↗ 1 helpful