Security

Reporting a vulnerability

Wradial installs a keyboard hook, replays input, and updates itself. That is a lot of trust for a small app to ask for, and the fastest way to keep it is to make reporting problems easy. If you have found something, please tell us before you tell anyone else.

Last updated: August 9, 2026

How to reach us

  • Email security@wradial.com. Machine-readable version: /.well-known/security.txt.
  • Include what you did, what happened, and the Wradial version (Settings → About). A rough proof of concept beats a polished writeup.
  • If you would rather not email, the feedback form reaches the same inbox — but please do not put exploit details in a public place.

What we promise

  • We confirm receipt within 5 business days and tell you whether we can reproduce it.
  • We tell you our fix plan and the version it will land in, and we let you know when it ships.
  • We credit you by name or handle in the release notes if you want the credit, and stay quiet about you if you don't.
  • We will not pursue legal action over research done in good faith under the rules below.

Wradial is a one-person project in open beta. There is no bug bounty and no payment — only a fast, honest reply and public credit. We would rather say that plainly than let you find out after the work.

In scope

  • The Wradial desktop app, its installer, and the automatic update channel.
  • wradial.com and its download endpoints.
  • The licensing and feedback backends (*.workers.dev endpoints reachable from the app).

Out of scope

  • Anything requiring physical access to an unlocked machine, or an attacker who already has administrator rights on it.
  • Findings that depend on the user deliberately configuring Wradial to run a hostile command — running commands you choose is the product.
  • Automated scanner output with no demonstrated impact, missing security headers on static pages, and SPF/DMARC opinions unaccompanied by a working spoof.
  • Denial of service, spam, or load testing against our endpoints. Please don't.

Rules for good-faith research

  • Use your own machine, your own licence key, and your own test data. Do not touch another user's data.
  • Do not exfiltrate data, pivot, or persist. Stop at proof and report.
  • Give us a reasonable window to fix before publishing — 90 days is our default, and we will usually be much faster.

What we do on our side

Releases are Authenticode-signed, and the app verifies both the hash and the publisher's signature before it runs an update. Licence entitlements are ECDSA-signed and the app holds only the public half. Crash reports and diagnostics are opt-in and scrubbed before they leave your machine — the details are in the privacy policy. We audit the codebase against a written brief and fix what we find; where we knowingly accept a risk instead, we write down why.

Contact

Security reports: security@wradial.com. Everything else: support@wradial.com.