Security

Report a Security Issue

If you have found a security vulnerability on winiba.com, please tell us. We review every legitimate report and aim to fix confirmed issues quickly.

Last updated: October 2026

How we protect the store

Encrypted connection

winiba.com is served over HTTPS with SSL/TLS encryption.

PCI DSS compliant payments

Payments are processed by Stripe and PayPal. Winiba does not store card data.

Ground rules

If you follow these principles when reporting an issue, we will not take legal action against you in response to your report. We ask that you:

  • give us reasonable time to review and fix the issue before disclosing it to anyone else;
  • do not access or interact with accounts without the owner’s consent;
  • make a good-faith effort to avoid privacy violations, service disruption and data destruction;
  • do not exploit the issue, including to demonstrate further risk or to access customer data;
  • comply with all applicable laws.

Bounty program

We may reward researchers who help protect the store. Bounties are awarded at our discretion, based on risk, impact and report quality. To be considered you must:

  • follow the ground rules above;
  • report a valid bug that poses a real risk to privacy or security;
  • email contact@winiba.com with the subject line Security Vulnerability Report, and not contact team members individually;
  • disclose any accidental privacy violation or disruption in your first report;
  • keep the report confidential until the issue is fixed.

Scope

In scope

  • The winiba.com website and storefront
  • Customer account and login systems
  • Checkout and payment redirection
  • Order management and personal data handling

Out of scope

  • Third-party plugins, CDNs and services outside our control
  • Denial-of-service (DoS/DDoS) attacks
  • Social engineering, spam and phishing
  • Physical security of our premises

Rewards

Rewards reflect impact and severity. Reports must include clear, reproducible steps; issues we cannot reproduce are not eligible. The first valid report of an issue receives the bounty, and several bugs with one root cause count as one report.

SeverityRewardExamples
Critical$200Remote code execution, vertical authentication bypass, SQL injection exposing sensitive data, full account or database takeover
High$100Lateral authentication bypass, disclosure of sensitive internal data, stored XSS affecting other users, local file inclusion
Medium$50Business logic flaws, insecure direct object references (IDOR)
LowRecognitionOpen redirects, reflected XSS, low-sensitivity information leaks

Report a vulnerability

Email us with the subject line “Security Vulnerability Report”.

Business hours: Mon–Fri: 9AM–10PM CT | Sat: 9AM–6PM CT | Sunday: Closed