goto-financial-public-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
14
In Scope
2
Out of Scope
In-Scope Assets (14)
AssetCategoryBountyQuick Links
*.findaya.co.idWILDCARDYes
*.findaya.comWILDCARDYes
*.gaming.gopayapi.comWILDCARDYes
*.go-pay.co.idWILDCARDYes
*.gofin.ioWILDCARDYes
*.gopayapi.comWILDCARDYes
*.gtflabs.ioWILDCARDYes
api.midtrans.comURLYes
app.midtrans.comURLYes
gopaymerchant.midtrans.comURLYes
https://apps.apple.com/id/app/gopay-transfer-pulsa-bills/id6446321594IOSYes-
https://play.google.com/store/apps/details?id=com.gojek.gopay&hl=idANDROIDYes
mokapos.comURLYes
www.midtrans.comURLYes
Out-of-Scope Assets (2)
AssetCategoryBounty
- All other Goto Financial assets not listed above are to be considered as out of scopeOTHERYes
- Any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHERYes
Scope Changes (50)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedwww.midtrans.comURLIn Scope19:08
Addedapp.midtrans.comURLIn Scope19:08
Addedhttps://apps.apple.com/id/app/gopay-transfer-pulsa-bills/id6446321594IOSIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.gojek.gopay&hl=idANDROIDIn Scope19:08
Addedgopaymerchant.midtrans.comURLIn Scope19:08
Added*.gopayapi.comWILDCARDIn Scope19:08
Addedapi.midtrans.comURLIn Scope19:08
Added*.gofin.ioWILDCARDIn Scope19:08
Added*.findaya.comWILDCARDIn Scope19:08
Added- all other goto financial assets not listed above are to be considered as out of scopeOTHEROut of Scope19:08
Added*.gaming.gopayapi.comWILDCARDIn Scope19:08
Added*.findaya.co.idWILDCARDIn Scope19:08
Added*.gtflabs.ioWILDCARDIn Scope19:08
Added- any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of Scope19:08
Addedmokapos.comURLIn Scope19:08
Added*.go-pay.co.idWILDCARDIn Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedapi.midtrans.comURLIn Scope00:51
Addedapp.midtrans.comURLIn Scope00:51
Added*.findaya.comWILDCARDIn Scope00:51
Addedhttps://play.google.com/store/apps/details?id=com.gojek.gopay&hl=idANDROIDIn Scope00:51
Addedwww.midtrans.comURLIn Scope00:51
Added*.gaming.gopayapi.comWILDCARDIn Scope00:51
Added*.gofin.ioWILDCARDIn Scope00:51
Added*.findaya.co.idWILDCARDIn Scope00:51
Added- all other goto financial assets not listed above are to be considered as out of scopeOTHEROut of Scope00:51
Addedhttps://apps.apple.com/id/app/gopay-transfer-pulsa-bills/id6446321594IOSIn Scope00:51
Added*.gopayapi.comWILDCARDIn Scope00:51
Addedgopaymerchant.midtrans.comURLIn Scope00:51
Added*.gtflabs.ioWILDCARDIn Scope00:51
Added- any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of Scope00:51
Addedmokapos.comURLIn Scope00:51
Added*.go-pay.co.idWILDCARDIn Scope00:51
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedwww.midtrans.comURLIn Scope21:40
Removed*.gaming.gopayapi.comWILDCARDIn Scope21:40
Removedhttps://apps.apple.com/id/app/gopay-transfer-pulsa-bills/id6446321594IOSIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.gojek.gopay&hl=idANDROIDIn Scope21:40
Removed*.gopayapi.comWILDCARDIn Scope21:40
Removedgopaymerchant.midtrans.comURLIn Scope21:40
Removedmokapos.comURLIn Scope21:40
Removed*.go-pay.co.idWILDCARDIn Scope21:40
Removedapi.midtrans.comURLIn Scope21:40
Removedapp.midtrans.comURLIn Scope21:40
Removed*.gofin.ioWILDCARDIn Scope21:40
Removed*.findaya.comWILDCARDIn Scope21:40
Removed*.findaya.co.idWILDCARDIn Scope21:40
Removed*.gtflabs.ioWILDCARDIn Scope21:40
Removed- any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of Scope21:40
Removed- all other goto financial assets not listed above are to be considered as out of scopeOTHEROut of Scope21:40
Added- any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of Scope00:33
Added- all other goto financial assets not listed above are to be considered as out of scopeOTHEROut of Scope00:33