PentestingHere
Log in Join

iFood: Bug Bounty Program

iFood: Bug Bounty Program on Bugcrowd · Bugcrowd Active

Official page

Scope

At a glance

  • Maximum payout: $3,750
  • Public disclosure: Not allowed
  • Managed by the platform: Yes
  • Safe harbour: Full

In scope

  • https://play.google.com/store/apps/details?id=br.com.brainweb.ifood&hl=pt_BR
  • https://apps.apple.com/br/app/ifood-pedir-comida-e-mercado/id483017239
  • https://www.ifood.com.br
  • https://marketplace.ifood.com.br
  • https://gestordepedidos.ifood.com.br
  • https://wsloja.ifood.com.br
  • https://*.movilepay.com
  • https://*.movilepay.com.br
  • https://shop.ifood.com.br
  • https://static-images.ifood.com.br
  • https://developer.ifood.com.br
  • https://api.fstr.rocks
  • https://rc.fstr.rocks
  • https://www.zoop.com.br
  • https://www.zoop.ws
  • https://www.minhaconta.zoop.com.br
  • https://dash.zoop.com.br/
  • https://contadigital.ifoodpago.com.br/
  • https://play.google.com/store/apps/details?id=br.com.movilepay.banking.application&hl=pt_BR
  • https://portal.iFoodpago.com.br

Out of scope

  • blog-empresas.ifood.com.br
  • blog-parceiros.ifood.com.br
  • *.ecomanda.com.br
  • *.ecomanda.app
  • *.allin.movilepay.com
  • *.starsoft.movilepay.com
  • Gestor de Pedidos - Desktop Client
  • *.openfinance.ifood.com.br
  • *.openfinance.ifoodpago.com.br

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback