About the Platform

About HunterRank

The community-driven platform where security researchers share honest reviews and ratings of bug bounty programs from every major platform.

Our Mission

Bug bounty programs vary wildly in quality, responsiveness, and fairness. Security researchers often spend hours triaging and reporting vulnerabilities only to face non-responsive programs, lowballed payouts, or unfair scope disputes. BugRank exists to bring transparency to the ecosystem. By letting the community rate and review programs anonymously, researchers can make informed decisions about where to invest their time and skills.

Rate Programs

Upvote or downvote bug bounty programs based on your experience. One vote per program keeps ratings authentic.

Write Reviews

Share detailed anonymous reviews about program responsiveness, payout fairness, scope clarity, and overall experience.

Discover Programs

Browse 140+ programs from HackerOne, Bugcrowd, Immunefi, Code4rena, Sherlock, Cantina, and many more.

Verified Accounts

Email-verified accounts required for voting and reviewing. Disposable emails blocked to ensure authentic feedback.

Anti-Spam Protection

Rate limiting, input sanitization, community flagging, and honeypot detection keep reviews authentic and spam-free.

19+ Platforms

We cover HackerOne, Bugcrowd, Immunefi, Code4rena, Sherlock, Cantina, Bugrap, Intigriti, YesWeHack, and more.

Platforms Covered

HackerOne
Bugcrowd
Immunefi
HackenProof
Code4rena
Sherlock
Cantina
Bugrap
Intigriti
YesWeHack
Open Bug Bounty
Synack
Cobalt
Apple
Microsoft
Meta
AWS
Samsung
Intel

Anti-Spam Measures

Verified Accounts

Email verification required. Disposable/temporary emails are blocked at registration.

Rate Limiting

1 vote per program per user, signup throttling, and comment cooldowns prevent abuse.

Input Sanitization

All user input is sanitized and validated. XSS payloads are detected and rejected.

Community Flagging

Report inappropriate comments. Auto-hidden after 3 community flags.

Honeypot Detection

Hidden form fields catch automated bots before they can submit.

Content Limits

Comments limited to 2000 characters. Password strength enforced with breach detection.