Security
If you have found a security problem in one of our plugins or on this site, we want to hear about it, and we would rather hear about it from you than read about it somewhere else.
How to report
Email support@bodholdtlabs.com with “Security” in the subject line. Tell us what you found, where, and how to reproduce it. A proof of concept helps but is not required, and a rough report is far better than no report.
We will acknowledge your email within five business days. We will tell you what we found when we have looked, whether we agree it is a problem, and when we expect to have a fix out. If we disagree, we will say why rather than going quiet.
What is in scope
Every plugin we publish, in every edition, free or paid. This website is in scope too.
Out of scope: reports generated by an automated scanner with no evidence the issue is real, findings in third party services we do not run, and anything that requires an attacker to already have administrator access to the site.
What we ask
Please give us a reasonable chance to ship a fix before you publish. Ninety days is a normal window and we will usually be much faster than that. Please do not run tests that degrade the service for anyone else, and please do not access, change, or keep data that is not yours.
What we will not do
We will not pursue or support legal action against anyone who reports a problem in good faith and follows this policy. If your report leads to a fix, we will credit you in the release notes when you want the credit and stay quiet when you do not.
To be plain about it: we do not run a bug bounty and we cannot pay for reports. We are a small operation and we would rather tell you that up front than have you find out after the work.
What happens next
When a fix is ready we publish it as a normal release and describe the problem in the changelog. Where a vulnerability in a product we sell is being actively exploited, we also report it to the authorities on the timeline the EU Cyber Resilience Act sets, and we tell affected users directly.