Security Policy

Public vulnerability disclosure policy

We take the security of Plathix seriously. If you believe you have discovered a security vulnerability affecting the Plathix WordPress plugin or plathix.com, please report it responsibly.

Reporting

Send security reports to: hello@plathix.com

  • Affected Plathix version
  • Affected functionality
  • Reproduction steps
  • Technical impact
  • Proof-of-concept information needed to reproduce the issue

Do not include unnecessary personal data or credentials.

Scope

  • Current Plathix WordPress plugin
  • plathix.com
  • Official Plathix endpoints/services explicitly identified as in scope

Third-party plugins, themes, hosting providers and services outside our control are not automatically in scope.

Coordinated disclosure

Please allow us reasonable time to investigate and, where appropriate, prepare a fix before publicly disclosing an unresolved vulnerability.

Response target

We aim to acknowledge security reports within 3–5 business days.

This is a target for acknowledgement, not a guarantee of resolution within that period.

Bounty

No monetary bounty is offered unless explicitly stated otherwise.

Updates

Where appropriate, security fixes for the public plugin will be distributed through official Plathix release channels, including WordPress.org where applicable.