Disclosure Lookup – a Caido plugin that finds where to report a vuln
FreeAbout Disclosure Lookup – a Caido plugin that finds where to report a vuln
Disclosure Lookup is a Caido plugin that enables security researchers and penetration testers to find the appropriate vulnerability disclosure contact for any host without leaving the Caido interface. Users can right-click on a request or a row in HTTP History and select "Find disclosure contact" to trigger a lookup. The plugin queries the free, unauthenticated lookup.disclose.io API and returns detailed information including the owning organization, jurisdiction, attribution confidence, and a ranked list of reporting channels such as security.txt, bug-bounty programs, VDP emails, PSIRT directories, and national CERTs. Each contact is marked as verified or unverified. The plugin also provides a dedicated sidebar page for manual lookups and is accessible via the command palette. It is part of the disclose.io Project and is open source.
Key Features
Pros & Cons
- Free and open source with no API key required
- Seamless integration into Caido's existing workflow
- Provides both verified and unverified contact status for trust assessment
- Multiple access methods: context menu, sidebar, command palette
- Backend isolation enhances security of outbound requests
- Part of the established disclose.io vulnerability disclosure ecosystem
- Requires Caido as the host application; not a standalone tool
- Depends on lookup.disclose.io database coverage; may not have entries for all hosts
- Only provides contact information; does not automate report submission