Plaid icon Plaid HackerOne


Target Policy
https://hackerone.com/plaid?type=team
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • secure.quovo.com
    URL
    critical
  • https://github.com/plaid/plaid-link-examples

    Plaid's drop-in client-side module for authentication. Available for web, mobile web and iOS.

    SOURCE_CODE
    critical
  • https://github.com/plaid/plaid-ruby

    The official Ruby bindings for the Plaid API. It's generated from our OpenAPI schema

    SOURCE_CODE
    critical
  • https://github.com/plaid/react-native-plaid-link-sdk

    Plaid Link for React Native

    SOURCE_CODE
    critical
  • https://github.com/plaid/plaid-link-android

    Plaid's drop-in client-side module for authentication. Available for web, mobile web and iOS.

    SOURCE_CODE
    critical
  • https://github.com/plaid/react-plaid-link

    React hooks and components for integrating with the Plaid Link drop module

    SOURCE_CODE
    critical
  • manage.blockscore.com
    URL
    critical
  • app.quovo.com
    URL
    critical
  • demo.plaid.com

    Demo Plaid developer integration

    URL
    medium
  • secure.plaid.com

    This is an alias for cdn.plaid.com

    URL
    critical
  • my.plaid.com

    Portal for customers to access their information as seen by Plaid apps they have permissioned. https://my.plaid.com

    URL
    critical
  • https://github.com/plaid/plaid-link-ios

    Plaid's drop-in client-side module for authentication. Available for web, mobile web and iOS.

    SOURCE_CODE
    critical
  • cdn.plaid.com

    This is on Amazon CloudFront, so the scope here is limited to our content and configuration issues.

    URL
    critical
  • production.plaid.com

    Plaid's developer API. Docs: https://plaid.com/docs

    URL
    critical
  • api.blockscore.com
    URL
    critical
  • plaid.com

    Plaid's marketing website, not full *.plaid.com

    URL
    medium
  • dashboard.plaid.com

    Plaid's developer dashboard

    URL
    critical
Target Scope Domains
  • api.blockscore.com
  • app.quovo.com
  • cdn.plaid.com
  • dashboard.plaid.com
  • demo.plaid.com
  • manage.blockscore.com
  • my.plaid.com
  • plaid.com
  • production.plaid.com
  • secure.plaid.com
  • secure.quovo.com
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
1 year, 1 month ago
Finished
  • Fleet: allkxss
  • Duration: 17.68 Minutes
  • Finished: 1 year, 1 month ago