Project note · Security
Help keep the refuge trustworthy.
If you believe you have found a security problem, please report it privately so it can be investigated without putting visitors at risk.
Where to write
Send the report to hello@magicalmanac.com. Include the affected page, what you observed, clear reproduction steps, and the impact you believe the issue could have.
What not to send
Do not email passwords, API keys, private visitor information, or other secrets. If evidence contains sensitive material, describe it first and wait for a safer transfer method.
Responsible testing
Please avoid disrupting the service, accessing data that is not yours, social engineering, denial-of-service testing, automated traffic at scale, or changing information. Stop once you have enough evidence to explain the issue.
Scope and response
Reports about magicalmanac.com and its first-party application are in scope. Magic Almanac is an independent, noncommercial project and does not promise a bounty, but thoughtful reports will be reviewed and handled as promptly as the project reasonably allows.