security.txt file has an expired expiry date
A security.txt file is a standard file placed on your website that tells security researchers how to responsibly report a vulnerability they discover on your site. An expired security.txt is treated as invalid under the official standard (RFC 9116). It signals to researchers that the contact information may be out of date, making it less likely that genuine vulnerability reports reach you. Update the Expires field in your security.txt file to a future date, and confirm the contact address listed is still actively monitored.
Why this matters
An expired security.txt is treated as invalid under the official standard (RFC 9116). It signals to researchers that the contact information may be out of date, making it less likely that genuine vulnerability reports reach you.
How to fix it
Update the Expires field in your security.txt file to a future date, and confirm the contact address listed is still actively monitored.