Vulnerability disclosure policy
Found a security problem on Voucher Magpie? Please tell us privately, so we can fix it before anyone misuses it.
Last updated 8 October 2026
What's covered
- This website, vouchermagpie.co.uk
- The Voucher Magpie browser extension for Chrome, Edge and Firefox
Shops, affiliate networks and other sites we link to aren't ours: please report problems with them to their owners.
Please don't
- Access, change or delete anyone else's data, beyond the minimum needed to show the problem
- Do anything that slows down or takes the site offline, including denial-of-service attacks and heavy automated scanning
- Try social engineering or phishing on our people, or any physical attack
- Tell anyone else about the problem until we've fixed it, or 90 days after you reported it, whichever comes first
We don't need reports of: missing security headers or cookie flags with no real impact, clickjacking on pages with no sensitive actions, rate limits on forms, email setup (SPF, DKIM, DMARC) findings, or software version numbers without a way to exploit them.
Report a vulnerability
What we promise
- We'll confirm we've received your report within 3 working days, and keep you updated while we fix it.
- If you've followed this policy in good faith, we won't take legal action against you or ask anyone else to.
- If you'd like, we'll thank you by name on this page once it's fixed.
We're a small business and don't run a paid bug bounty.
This policy is also listed in our security.txt file. For how we look after data generally, see security and ISO 27001.