Back to Home
Legal

Security & Responsible Disclosure

Last updated · July 24, 2026

We appreciate the security research community. If you discover a vulnerability in PLZ FRUIT, please report it privately using the process below. We will not pursue legal action against researchers who follow this policy in good faith.

1. In Scope

  • The PLZ FRUIT web application on our official domains.
  • API endpoints used by the Site.
  • Authentication, authorization, and account-management flows.

2. Out of Scope

  • Denial-of-service, volumetric attacks, or stress tests.
  • Social engineering of staff, users, or third-party vendors.
  • Physical attacks against our infrastructure.
  • Reports based solely on automated scanner output without proof of impact.
  • Findings on third-party services (e.g. our hosting provider) — please report those to the vendor.

3. Rules of Engagement

  • Only test against accounts you own.
  • Do not access, modify, or delete data belonging to other users.
  • Do not run automated scanners that generate high traffic.
  • Give us a reasonable time to fix the issue before public disclosure.

4. How to Report

Send a detailed report through the contact channels in your account settings or via our support Discord's private security channel. Please include:

  • A clear description of the vulnerability.
  • Steps to reproduce, ideally with a proof-of-concept.
  • Your assessment of impact and affected endpoints.
  • Any relevant screenshots, logs, or request captures.

5. Our Commitment

  • We will acknowledge valid reports promptly.
  • We will keep you updated on remediation progress.
  • We will credit researchers on request once the issue is resolved.

6. Safe Harbor

Good-faith security research under this policy is authorized, and we will not initiate legal action against researchers who comply. If a third party pursues legal action, we will make it clear that your activity was authorized.

Powered by Blox Fruits Collectors · We are not affiliated with Roblox Corporation.