Security Policy
Public vulnerability disclosure policy
We take the security of Plathix seriously. If you believe you have discovered a security vulnerability affecting the Plathix WordPress plugin or plathix.com, please report it responsibly.
Reporting
Send security reports to: hello@plathix.com
- Affected Plathix version
- Affected functionality
- Reproduction steps
- Technical impact
- Proof-of-concept information needed to reproduce the issue
Do not include unnecessary personal data or credentials.
Scope
- Current Plathix WordPress plugin
- plathix.com
- Official Plathix endpoints/services explicitly identified as in scope
Third-party plugins, themes, hosting providers and services outside our control are not automatically in scope.
Coordinated disclosure
Please allow us reasonable time to investigate and, where appropriate, prepare a fix before publicly disclosing an unresolved vulnerability.
Response target
We aim to acknowledge security reports within 3–5 business days.
This is a target for acknowledgement, not a guarantee of resolution within that period.
Bounty
No monetary bounty is offered unless explicitly stated otherwise.
Updates
Where appropriate, security fixes for the public plugin will be distributed through official Plathix release channels, including WordPress.org where applicable.