Linktree HackerOne


Target Policy
https://hackerone.com/linktree?type=team
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • ee.linktr.admin
    GOOGLE_PLAY_APP_ID
    critical
  • http://*.odesli.co
    WILDCARD
    critical
  • http://*.song.link
    WILDCARD
    critical
  • http://*.album.link
    WILDCARD
    critical
  • http://*.artist.link
    WILDCARD
    critical
  • http://*.pods.link
    WILDCARD
    critical
  • http://*.playlist.link
    WILDCARD
    critical
  • http://*.mylink.page
    WILDCARD
    critical
  • http://*.linktree-extensions.com
    WILDCARD
    critical
  • http://*.tr.ee
    WILDCARD
    critical
  • http://*.linktree.com
    WILDCARD
    critical
  • http://*.odesli.com
    WILDCARD
    critical
  • http://*.songlink.io
    WILDCARD
    critical
  • http://*.linktr.ee
    WILDCARD
    critical
  • https://linktr.ee

    # Linktree Website
    https://linktr.ee is the Linktree marketing website. It is *not* the Linktree application.

    ## Routes in-scope:
    * https://linktr.ee
    * https://linktr.ee/s/*

    URL
    critical
  • https://linktr.ee/admin*

    # Linktree Admin
    The Linktree admin application is how our users configure and publish their Linktree, it is the central and most critical part of the Linktree value proposition for our users.

    ## Routes In-Scope
    * https://linktr.ee/login
    * https://linktr.ee/register
    * https://linktr.ee/admin*

    WILDCARD
    critical
  • *.odesli.co
    WILDCARD
    critical
  • *.song.link
    WILDCARD
    critical
  • *.album.link
    WILDCARD
    critical
  • *.artist.link
    WILDCARD
    critical
  • *.pods.link
    WILDCARD
    critical
  • *.playlist.link
    WILDCARD
    critical
  • *.mylink.page
    WILDCARD
    critical
  • *.linktr.ee
    WILDCARD
    critical
  • *.linktree-extensions.com
    WILDCARD
    critical
  • *.tr.ee
    WILDCARD
    critical
  • *.linktree.com
    WILDCARD
    critical
  • *.odesli.com
    WILDCARD
    critical
  • *.songlink.io
    WILDCARD
    critical
  • ee.linktr.admin
    APPLE_STORE_APP_ID
    critical
Target Scope Domains
  • album.link
  • artist.link
  • linktr.ee
  • linktree-extensions.com
  • linktree.com
  • mylink.page
  • odesli.co
  • odesli.com
  • playlist.link
  • pods.link
  • song.link
  • songlink.io
  • tr.ee
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
1 year, 1 month ago
Finished
  • Fleet: allkxss
  • Duration: 31.15 Minutes
  • Finished: 1 year, 1 month ago