If you discover a possible vulnerability in the Code Card Library website or account system, use the private Report a Bug workflow.
Clearly identify the report as a security issue and include the affected feature or route, reproduction steps, expected impact, and relevant browser or environment information.
If the security concern involves a specific published Code Card rather than the website itself, use the card's Report action and choose Security or unsafe code.
When testing or reporting security issues:
do not access another user's private content
do not perform denial-of-service or destructive testing
do not deploy malware, persistence, or social-engineering tests
do not publish private data you encounter
do not include passwords, session cookies, reset links, or API secrets
stop testing if continuing could damage data or affect other users
Code Card does not currently operate a paid bug-bounty program.