BLT logo

OWASP BLT

OWASP Bug Logging Tool

OWASP Project • AGPLv3 Licensed

One landing page for public bugs, secure disclosures, and contributor momentum.

OWASP BLT gives teams a practical front door to collect issue reports, route sensitive vulnerabilities to BLT-Zero, and keep community reporting transparent through a live leaderboard.

12
Bugs reported
2
Domains
4
Active reporters

What OWASP BLT gives your team

Built for practical bug intake: clear public reporting, safe vulnerability handling, and community visibility in one workflow.

Public bug reports

Capture 404/500 issues, UI regressions, performance problems, typo fixes, and policy violations in one place.

Anonymous intake via BLT-API

Contributors can submit reports without exposing account identity when privacy is important.

Secure vulnerability path

Route critical security disclosures through BLT-Zero with zero-log, zero-tracking guarantees.

Live leaderboard

Recognition stays visible through an auto-refreshed leaderboard generated from issue activity.

Report issues on any website

BLT covers the entire internet — report bugs, broken pages, or security problems on any domain, not just your own.

Earn rewards for every report

Reporters earn BACON tokens for accepted bug reports, turning community contributions into tangible recognition.

How teams use OWASP BLT daily

Keep public issue intake simple, keep sensitive security reports private, and keep contributor trust high with transparent tracking.

Report a public bug

GitHub template or anonymous submission

Supported issue categories include:

404 / 500 errors Functional issues Performance Slow loading Typos Design issues IP / trademark License violations
Report a bug

Report a vulnerability

Private channel powered by BLT-Zero

For sensitive security findings, use a private disclosure route with stronger safety guarantees:

Zero logs Zero tracking Zero storage Encrypted transport
Only the report ID and status are visible to the organization. Sensitive vulnerability payloads are not stored in the receiving server.
Report vulnerability

Recent bug reports

Latest community-submitted issues from this repository

View all reports
Bug screenshot

www.owasp.community favicon[BUG] join chapter button does not work

Mar 1, 2026
Armaansaxena's avatar

I'd like to work on this. I'll investigate the button's event handler and form submission logic and share my findings here before submitting a fix

2 comments

How it works

Three practical steps to improve web quality and security response.

1. Spot a bug

Find a broken flow, performance issue, typo, visual regression, or policy concern.

2. Submit report

Use the GitHub template for normal issues or submit anonymously through BLT-API.

3. Build trust

Accepted reports improve your leaderboard rank and help teams triage faster.

Leaderboard

Updated Mar 4, 2026

Submit report
Rank Reporter
🥇DonnieBLT's avatarDonnieBLT
7
🥈ananya-09's avatarananya-09
3
🥉kittenbytes's avatarkittenbytes
1
#4sidd190's avatarsidd190
1

Leaderboard refreshes every 6 hours via GitHub Actions. View all reports on GitHub.

Top Commenters

Rank Commenter
🥇ananya-09's avatarananya-09
2
🥈sidd190's avatarsidd190
2
🥉azizrebhi's avatarazizrebhi
2
#4Nachiket-Roy's avatarNachiket-Roy
1
#5yogeshwarithombare's avataryogeshwarithombare
1
#6Armaansaxena's avatarArmaansaxena
1
#7mdkaifansari04's avatarmdkaifansari04
1
#8DonnieBLT's avatarDonnieBLT
1

Top Domains

Rank Domain
🥇owaspblt.org faviconowaspblt.org
10
🥈www.owasp.community faviconwww.owasp.community
2