Feed
Bounty Rolling

ProjectDiscovery OSS Bounty Program

ProjectDiscovery pays bounties for bug fixes, features, performance work and docs in its open source security tools. Each issue shows its reward. Open to anyone, no deadline.

The ProjectDiscovery OSS Bounty Program pays contributors for work on the company's open source security tools. Bounty amounts depend on complexity and impact, and every issue shows its reward up front.

Four kinds of contribution qualify: bug fixes for confirmed issues, performance improvements, feature implementations that the community needs, and documentation and testing. The projects in scope are Nuclei, Katana, Subfinder, Httpx, Naabu, ShuffleDNS, DNSx, TLSx, Vulnx and URLFinder.

Anyone can take part, regardless of location, background or credentials. ProjectDiscovery says the quality of the contribution is what matters.

To join, read the program guidelines in the oss-bounty-program repository on GitHub, then browse the issues with the bounty label across the ProjectDiscovery repositories. The program has no deadline and has been running since February 2026.

ProjectDiscovery says the program is built on transparency, fairness, respect and community, with timely reviews, clear communication and prompt payment.

Source · projectdiscovery.io/blog/announcing-the-projectdiscovery-oss-bounty-program Published 2 February 2026 · Added here 6 September 2026