Vulnerability disclosure policy

Found a security problem in PowerSEC? We want to hear about it. This page explains how to report it and what you can expect from us.

How to report

  • Email [email protected].
  • Say what you found and where: the URL or endpoint, or the plugin file and version.
  • Include the steps to reproduce it and the impact you expect.

In scope

  • The powersec.io website and the PowerSEC dashboard.
  • The PowerSEC Central API that connected sites talk to.
  • The PowerSEC WordPress plugin, in its current version on WordPress.org.

Out of scope

  • Third-party plugins, themes or hosting not made by PowerSEC.
  • Sites you don’t own.
  • Denial of service and volume testing.
  • Social engineering and physical attacks.
  • Automated-scanner output without a working proof of concept.
  • Missing best-practice headers or SPF/DMARC records with no demonstrated impact.
  • Self-XSS, and clickjacking on pages with no sensitive action.

What we do

  • We aim to acknowledge your report within 3 business days.
  • We work with you on a fix and keep you updated until it ships.
  • We ask for up to 90 days from our acknowledgement to ship a fix before you publish; once a fix is released we can agree an earlier date, and we will tell you if we need more time.

Safe harbor

  • We won’t pursue good-faith researchers who follow this policy and avoid privacy violations, data destruction, or service disruption. In practice:
  • Test only accounts and sites you own or are allowed to test.
  • Don’t access, change, or delete anyone else’s data.
  • Don’t disrupt the service: no denial-of-service or high-volume testing.
  • Follow the coordinated-disclosure timeline above before you make the issue public.

Our contact details are also published in security.txt. For how PowerSEC protects your sites and data, see Security & trust.

[email protected]
Hacked? Talk to us