How to report
- Email [email protected].
- Say what you found and where: the URL or endpoint, or the plugin file and version.
- Include the steps to reproduce it and the impact you expect.
In scope
- The powersec.io website and the PowerSEC dashboard.
- The PowerSEC Central API that connected sites talk to.
- The PowerSEC WordPress plugin, in its current version on WordPress.org.
Out of scope
- Third-party plugins, themes or hosting not made by PowerSEC.
- Sites you don’t own.
- Denial of service and volume testing.
- Social engineering and physical attacks.
- Automated-scanner output without a working proof of concept.
- Missing best-practice headers or SPF/DMARC records with no demonstrated impact.
- Self-XSS, and clickjacking on pages with no sensitive action.
What we do
- We aim to acknowledge your report within 3 business days.
- We work with you on a fix and keep you updated until it ships.
- We ask for up to 90 days from our acknowledgement to ship a fix before you publish; once a fix is released we can agree an earlier date, and we will tell you if we need more time.
Safe harbor
- We won’t pursue good-faith researchers who follow this policy and avoid privacy violations, data destruction, or service disruption. In practice:
- Test only accounts and sites you own or are allowed to test.
- Don’t access, change, or delete anyone else’s data.
- Don’t disrupt the service: no denial-of-service or high-volume testing.
- Follow the coordinated-disclosure timeline above before you make the issue public.
Our contact details are also published in security.txt. For how PowerSEC protects your sites and data, see Security & trust.
[email protected]