Responsible Disclosure
Last updated: August 2026
Our Commitment
WP Secure Audit believes in responsible, coordinated disclosure. If you believe you've found a security vulnerability in our own website or infrastructure, we want to hear from you before it's made public.
Scope
This policy applies to wpsecureaudit.com and infrastructure we directly operate. It does not apply to client websites we've audited — vulnerabilities found on client sites during an authorized engagement are reported directly to that client under the terms of the engagement.
How to Report
Email security@wpsecureaudit.com with a description of the vulnerability, steps to reproduce, and any proof-of-concept material. Please encrypt sensitive details using our PGP key, available on request.
What We Ask
- Give us reasonable time to investigate and remediate before any public disclosure — we target 90 days.
- Avoid accessing, modifying, or deleting data that isn't yours.
- Do not perform testing that could degrade service availability, such as denial-of-service attacks.
- Do not use automated scanners against production systems without prior written permission.
What You Can Expect From Us
- Acknowledgement of your report within 2 business days.
- An honest assessment of severity and expected remediation timeline.
- Credit in our security advisories page, if desired.
- No legal action against good-faith researchers who follow this policy.
Out of Scope
Social engineering, physical security testing, and spam/phishing simulations against our staff are not covered by this policy and should not be attempted.