Found a security issue in MxInspector or on this site? Email hello@timothymaurer.nl with MxInspector security in the subject, and give me time to fix it before you publish. Please leave client data out of your report.
How to report
Email hello@timothymaurer.nl with MxInspector security in the subject. Please include:
- what you found and what an attacker could do with it;
- the steps to reproduce it;
- the MxInspector version, your browser and its version;
- whether it concerns the extension or this website.
Leave out real data: no names, records, credentials or URLs from client applications. A description or a test app is enough.
What is in scope
- The MxInspector browser extension, current version, for Chrome, Edge and Firefox.
- This website, mxinspector.com.
Issues in a Mendix application itself belong with the owner of that application, or with Mendix through its own disclosure process. MxInspector only reads what such an application already sends to the browser.
What happens next
MxInspector is a personal project, so reports are read and answered by me personally. Please give me a reasonable time to look into it and ship a fix before you publish anything. If you would like to be credited for a report, say so and I will name you in the changelog.
There is no bug bounty: MxInspector is free, and there is no budget behind it.
Built to stay read-only
- No requests of its own. The only exception is the doc-endpoint probe in the Security section, which sends up to four HEAD requests to your own app when you click its button.
- No data collection, no analytics, no remote code. Everything ships inside the package.
- The panel and the Agent API only exist on a page after you click the icon, and the Agent API starts switched off.
- It shows only what the Mendix runtime sent to your session. What your role cannot read never reaches the browser.
The permissions and the privacy policy explain each of these in detail.
security.txt
The same contact details are available in machine-readable form at /.well-known/security.txt, the standard location (RFC 9116) that security researchers and scanners check.