Security and supplier information
How to report a vulnerability in a plugin we publish, the timelines we commit to, and the supplier details a regulated customer needs.
Last updated:
Reporting a vulnerability
Email [email protected] with the plugin, the version and enough detail to reproduce the issue. The machine-readable version of this contact is published at plogins.com/.well-known/security.txt under RFC 9116. The full coordinated disclosure policy, covering both plogins.com and every plugin we publish, is at wppoland.com/en/security-policy/. Please do not test against a site that is not yours.
What we commit to, and by when
We acknowledge a report within 2 working days and give a first assessment within 5. For a confirmed critical vulnerability in a plugin we publish, we ship a patch or withdraw the plugin from distribution within 7 days of confirmation, and we tell you which we did. We publish an advisory within 14 days of the patch. If we cannot meet a deadline we say so and publish a workaround rather than going quiet.
No bug bounty, but credit and written confirmation
We run no bug bounty and pay no rewards; we would rather say so plainly than advertise a programme we cannot fund. We do credit reporters by name or handle in the release notes and the advisory, if they want the credit, and we confirm in writing that a report was valid and what we did about it.
Telling a security release apart from a feature release
A security release says so. Its changelog entry begins with Security and a severity of critical, high, medium or low, and the same version carries an upgrade notice, which is the text WordPress shows in the update row in wp-admin. A security release carries the fix alone, with no features bundled in, so it can be taken under change control without reviewing unrelated code.
If you are a customer under NIS2 or the Polish cybersecurity act
By publishing plugins we are a software supplier, a role the Polish national cybersecurity act names separately from a service provider, both in its ICT supply chain requirements and in the high-risk supplier mechanism. If you must document us in your supply chain, this page together with the coordinated disclosure policy is the document to reference. Ask us and we will confirm the details in writing on company letterhead, including the versions you run and when they were last updated. We cannot file incident notifications to authorities on your behalf, because that duty sits with the covered entity and not with its supplier; we can supply the technical detail for your own filing, inside your reporting window if you tell us what it is.
This document is product information and does not replace individual legal advice.