Magic Almanac

Project record

Return to the almanac

Project note · Security

Help keep the refuge trustworthy.

If you believe you have found a security problem, please report it privately so it can be investigated without putting visitors at risk.

Where to write

Send the report to hello@magicalmanac.com. Include the affected page, what you observed, clear reproduction steps, and the impact you believe the issue could have.

What not to send

Do not email passwords, API keys, private visitor information, or other secrets. If evidence contains sensitive material, describe it first and wait for a safer transfer method.

Responsible testing

Please avoid disrupting the service, accessing data that is not yours, social engineering, denial-of-service testing, automated traffic at scale, or changing information. Stop once you have enough evidence to explain the issue.

Scope and response

Reports about magicalmanac.com and its first-party application are in scope. Magic Almanac is an independent, noncommercial project and does not promise a bounty, but thoughtful reports will be reviewed and handled as promptly as the project reasonably allows.