Report a security issue
We welcome responsible reports about weaknesses in the website, owner and staff areas, data pipeline and repository.
Last reviewed 31 August 2026
How to report
Email [email protected] with the affected URL or component, steps to reproduce, the impact you believe is possible, and the smallest safe proof. Do not include credentials, personal data or destructive proof in the first message.
We aim to acknowledge a report within two business days and provide a status update at least every ten business days until it is closed. This is not a bug-bounty offer or a promise of payment.
Good-faith research
- Test only accounts and data you own or have written permission to use.
- Stop when you have shown that unauthorised access is possible. Do not retain, alter, download or disclose another person's data.
- Do not degrade availability, send bulk messages, test social engineering or target a supplier's infrastructure.
- Allow reasonable time for investigation and remediation before disclosure.
If you follow this policy, we will treat the work as good-faith security research and will not knowingly pursue action against you for the research. This does not authorise activity that is unlawful or outside systems controlled by What Gyms Cost.
Scope
In scope: whatgymscost.co.uk and its www alias; WGC owner and staff authentication and authorised application functions; WGC database policies and API functions reached through the public application; and this repository's build and deployment configuration.
Out of scope without separate written permission: denial-of-service, load or volume testing; phishing, social engineering or physical testing; gym operators' sites and APIs; supplier infrastructure; and automated submission to public forms or authentication endpoints at scale.
Use the smallest proof needed and redact tokens and personal data. Provider vulnerabilities should go to the provider unless the weakness is in WGC's configuration or use of that provider.