This is just "feel-good" bullshit that doesn't actually solve any real problem. In my life, I have only reported two different vulnerabilities to two different vendors. One of them didn't care at all. They were transmitting usernames and passwords in plaintext and I actually showed one of their engineers this, live, in person, and he just shrugged. The other one told me something to the effect of "yes, this is very s…
>In my life, I have only reported two different vulnerabilities to two different vendors. Interesting. I don't think this is for you. Ever have the task of needing to report a security issue to 10k sites and wish you could have any hope of automating it? I certainly haven't. More like 100k! Don't be so negative when people try to do good.
The example security.txt for this site currently has a twitter handle as the contact. How are you going to automate that?