Responsible Disclosure Policy
We take security seriously. If you've found a vulnerability in our plugin or infrastructure, we want to hear from you. Help us protect thousands of WordPress sites.
We Acknowledge
We respond within 48 hours and confirm we have received your report.
We Fix & Credit
We patch the issue and credit you publicly in our changelog (if you wish).
How to Report a Vulnerability
Please send a detailed email to [email protected] with the following information:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce the issue (including any proof-of-concept code).
- Plugin version, WordPress version, and PHP version where the issue was discovered.
- Your contact details so we can follow up and credit you.
?? PGP Encryption: If you need to send sensitive exploit data, please email us first to request our public PGP key before transmitting any details.
Our Commitment to You
48-Hour Acknowledgement
We will confirm receipt of your report within 48 hours.
Fix Timeline
We will provide a realistic timeline for deploying a patch.
Patch Notification
We will notify you immediately once the fix is deployed.
Public Credit
We will acknowledge your contribution in our changelog, if you wish.
Rules of Engagement
To maintain a safe and productive disclosure process, we ask that you follow these guidelines:
- Do NOT exploit the vulnerability to access, modify, or delete user data.
- Do NOT perform any attacks that could degrade performance (e.g., DDoS, brute-force).
- Do NOT publicly disclose the vulnerability until we have had reasonable time to patch it (90-day coordinated disclosure).
- DO test only against your own installations or with explicit written permission.
- DO act in good faith to avoid privacy violations, disruption of service, or data destruction.
Scope
In Scope
- nexura-security WordPress plugin
- nexurasecurity.com website
- nexura-security-pro plugin
- Any API endpoints we operate
Out of Scope
- Third-party services (Freemius, Stripe)
- Spam or social engineering attacks
- Physical security attacks
- Denial of service (DoS/DDoS)
Found Something?
We appreciate your effort in keeping our users safe. Thank you for being part of our security community.
Report a Vulnerability