Cloudflare Adds Security.txt Setup Wizard
Blog post from Socket
Cloudflare has introduced a new setup wizard to simplify the creation and management of security.txt files for vulnerability disclosure on websites. This format allows organizations to specify their security policies and suitable reporting channels, enhancing the process of vulnerability reporting. Previously, setting up security.txt involved a complex manual process through Cloudflare Workers, but the new wizard, accessible under Security settings and available on Cloudflare's free plan, aims to facilitate broader adoption. Despite its benefits, the security.txt file has been attracting spam bots, leading to concerns about its implementation, as users have reported receiving spam messages after deploying it. To mitigate this, Cloudflare provides options for the Contact field, allowing users to choose between an email address, phone number, or URL link, while the email is not mandatory. This initiative, first noticed by Troy Hunt, could significantly increase the adoption of security.txt across the web, as Cloudflare serves a substantial portion of internet traffic.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.