A mention of the bug bounty was posted over on the /r/php subreddit earlier and there’s already some good feedback about it. First off, it sends a message to the wider world of developers that it’s time to take (PHP) security seriously. Bug bounties have become a pretty common place thing in the security world, for software and hardware alike. I think with so much of the PHP world turing to smaller packages, it’s a tough problem to figure out. I’d love to help make bug bounties a more wide-spread thing in the PHP world.