Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

wonder-vdp

HackerOneView on HackerOne
RawAI Enhanced
31
In Scope
4
Out of Scope
In-Scope Assets (31)
AssetCategoryBountyQuick Links
*.grubhub.comWILDCARDNo
*.jo30.comWILDCARDNo
*.seamless.comWILDCARDNo
*.tapingo.comWILDCARDNo
*.tastemade.comWILDCARDNo
302920553IOSNo-
971197898IOSNo-
976642810IOSNo-
api-merchant-gtm.grubhub.com URLNo
auth.grubhub.comURLNo
com.blueapron.blueapron.releaseANDROIDNo
com.grubhub.androidANDROIDNo
com.tastemade.appANDROIDNo
http://www.blueapron.com/apiURLNo
http://www.blueapron.com/graphqlURLNo
https://*.wonder.comWILDCARDNo
https://blog.blueapron.com/URLNo
https://core-api.production.claim.coURLNo
https://core-api.staging.claim.coURLNo
https://cs-dashboard.production.claim.co/graphqlURLNo
https://cs-dashboard.staging.claim.co/graphqlURLNo
https://order.wonder.comURLNo
restaurant.grubhub.comURLNo
sensor.grubhub.comURLNo
tastemade.comURLNo
www.blueapron.comURLNo
www.grubhub.comURLNo
www.jo30.comURLNo
www.menupages.comURLNo
www.seamless.comURLNo
www.tapingo.comURLNo
Out-of-Scope Assets (4)
Scope Changes (103)
Mar 31, 2026
ChangeAssetCategoryScopeTime
Addedhttps://core-api.staging.claim.coURLIn Scope22:21
Addedhttps://core-api.production.claim.coURLIn Scope22:21
Addedhttps://cs-dashboard.production.claim.co/graphqlURLIn Scope22:21
Addedhttps://cs-dashboard.staging.claim.co/graphqlURLIn Scope22:21
Addedhttps://core-api.staging.claim.coURLIn Scope22:21
Addedhttps://core-api.production.claim.coURLIn Scope22:21
Addedhttps://cs-dashboard.staging.claim.co/graphqlURLIn Scope22:21
Addedhttps://cs-dashboard.production.claim.co/graphqlURLIn Scope22:21
Removed976642810IOSIn Scope18:21
Removed302920553IOSIn Scope18:21
Removedcom.blueapron.blueapron.releaseANDROIDIn Scope18:21
Removedcom.grubhub.androidANDROIDIn Scope18:21
Addedcom.tastemade.appANDROIDIn Scope18:21
Added971197898IOSIn Scope18:21
Addedcom.tastemade.appANDROIDIn Scope18:21
Added971197898IOSIn Scope18:21
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttp://www.blueapron.com/graphqlURLIn Scope19:12
Added*.grubhub.comWILDCARDIn Scope19:12
Addedwww.seamless.comURLIn Scope19:12
Addedsupport.grubhub.comURLOut of Scope19:12
Addedapi-merchant-gtm.grubhub.comURLIn Scope19:12
Addedtastemade.comURLIn Scope19:12
Addedsupport.blueapron.comURLOut of Scope19:12
Addedsupport.seamless.comURLOut of Scope19:12
Addedhttp://www.blueapron.com/apiURLIn Scope19:12
Addedwww.menupages.comURLIn Scope19:12
Addedhttps://order.wonder.comURLIn Scope19:12
Added*.seamless.comWILDCARDIn Scope19:12
Addedcom.grubhub.androidANDROIDIn Scope19:12
Addedwww.blueapron.comURLIn Scope19:12
Added*.jo30.comWILDCARDIn Scope19:12
Addedsensor.grubhub.comURLIn Scope19:12
Addedcom.blueapron.blueapron.releaseANDROIDIn Scope19:12
Added*.tapingo.comWILDCARDIn Scope19:12
Addedwww.tapingo.comURLIn Scope19:12
Added976642810IOSIn Scope19:12
Addedauth.grubhub.comURLIn Scope19:12
Addedhttp://support.wonder.comURLOut of Scope19:12
Added*.wonder.comWILDCARDIn Scope19:12
Addedwww.jo30.comURLIn Scope19:12
Added*.tastemade.comWILDCARDIn Scope19:12
Addedhttps://blog.blueapron.com/URLIn Scope19:12
Addedwww.grubhub.comURLIn Scope19:12
Addedrestaurant.grubhub.comURLIn Scope19:12
Added302920553IOSIn Scope19:12
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedauth.grubhub.comURLIn Scope01:12
Addedwww.tapingo.comURLIn Scope01:12
Addedwww.jo30.comURLIn Scope01:12
Addedrestaurant.grubhub.comURLIn Scope01:12
Addedtastemade.comURLIn Scope01:12
Addedhttps://blog.blueapron.com/URLIn Scope00:43
Addedhttp://www.blueapron.com/graphqlURLIn Scope00:43
Added*.grubhub.comWILDCARDOut of Scope00:43
Addedwww.seamless.comURLIn Scope00:43
Added976642810IOSIn Scope00:43
Addedsensor.grubhub.comURLIn Scope00:43
Addedcom.blueapron.blueapron.releaseANDROIDIn Scope00:43
Addedhttp://www.blueapron.com/apiURLIn Scope00:43
Added*.tapingo.comWILDCARDIn Scope00:43
Addedsupport.blueapron.comURLOut of Scope00:43
Addedsupport.grubhub.comURLOut of Scope00:43
Addedapi-merchant-gtm.grubhub.comURLIn Scope00:43
Addedwww.grubhub.comURLIn Scope00:43
Addedwww.menupages.comURLIn Scope00:43
Added*.wonder.comWILDCARDOut of Scope00:43
Addedsupport.seamless.comURLOut of Scope00:43
Added*.jo30.comWILDCARDIn Scope00:43
Added*.seamless.comWILDCARDOut of Scope00:43
Added302920553IOSIn Scope00:43
Addedcom.grubhub.androidANDROIDIn Scope00:43
Added*.tastemade.comWILDCARDIn Scope00:43
Addedwww.blueapron.comURLIn Scope00:43
Addedhttps://order.wonder.comURLOut of Scope00:43
Addedhttp://support.wonder.comURLOut of Scope00:43
Feb 21, 2026
ChangeAssetCategoryScopeTime
Addedhttps://blog.blueapron.com/URLIn Scope19:12
Addedhttps://order.wonder.comURLIn Scope19:12
Added*.wonder.comWILDCARDIn Scope19:12
Addedhttp://www.blueapron.com/graphqlURLIn Scope19:12
Added*.grubhub.comWILDCARDIn Scope19:12
Addedwww.blueapron.comURLIn Scope19:12
Added*.seamless.comWILDCARDIn Scope19:12
Addedwww.grubhub.comURLIn Scope19:12
Addedwww.menupages.comURLIn Scope19:12
Addedwww.seamless.comURLIn Scope19:12
Added*.tapingo.comWILDCARDIn Scope19:12
Addedwww.tapingo.comURLIn Scope19:12
Addedwww.jo30.comURLIn Scope19:12
Added*.jo30.comWILDCARDIn Scope19:12
Addedrestaurant.grubhub.comURLIn Scope19:12
Addedapi-merchant-gtm.grubhub.comURLIn Scope19:12
Added976642810IOSIn Scope19:12
Added302920553IOSIn Scope19:12
Addedsensor.grubhub.comURLIn Scope19:12
Addedcom.blueapron.blueapron.releaseANDROIDIn Scope19:12
Addedcom.grubhub.androidANDROIDIn Scope19:12
Addedhttp://www.blueapron.com/apiURLIn Scope19:12
Addedauth.grubhub.comURLIn Scope19:12
Addedtastemade.comURLIn Scope19:12
Added*.tastemade.comWILDCARDIn Scope19:12
Addedhttp://support.wonder.comURLOut of Scope19:12
Addedsupport.blueapron.comURLOut of Scope19:12
Addedsupport.grubhub.comURLOut of Scope19:12
Addedsupport.seamless.comURLOut of Scope19:12