Skip to content
Flowpane

Use case

Level 2 / Context

Security disclosure

security.txt tells a researcher how to report a vulnerability. RFC 9116 requires an expiry date so stale contacts stop being trusted, which means a file nobody renews fails on a date you could have known.

Without a check

What goes wrong

  • Expires passes and the file stops counting, usually discovered in an audit.
  • The file is served from the wrong path, or as an HTML page.
  • Expires is set years ahead, which RFC 9116 advises against.

With Flowpane

What changes

  • Scores an expired file at zero. It is a hard rule, not a warning.
  • Flags files that expire within 30 days, and expiry dates more than a year ahead.
  • Checks required fields, date formats, and the canonical location.

What it looks like in Flowpane

Illustrative
  • Warningsecurity.txtExpires in 21 days.
  • Warningsecurity.txtExpires is more than a year away.
  • Advicesecurity.txtAdd Canonical and Preferred-Languages.

Files involved

Most relevant for

See what your sites are claiming.

Add an origin and get a score, the gaps, and the evidence behind each one. Then Flowpane keeps checking, so the answer stays current.

Free during the beta. Flowpane only reads your origin.