EN

Security policy and vulnerability disclosure

5.00/5 - (17 votes)
5 min read
Reference

#Reporting a vulnerability

Email [email protected]. Include the affected URL or plugin slug, the version you tested, and enough detail for us to reproduce the issue. A short proof-of-concept helps more than a scanner report.

You do not need to encrypt the first message. If the finding warrants it, we will agree an encrypted channel in the reply. We currently publish no PGP key, and we would rather say that plainly than list a key file that does not exist.

We answer in English, Polish and German.

#What this policy covers

It covers wppoland.com, plogins.com, and every plugin we publish under the plogins name, whether distributed through the WordPress.org directory or from our own site.

It does not cover third-party plugins, themes or hosting that we merely install or maintain on a client’s behalf. Those belong to their authors and we will forward a report if you ask, but we cannot patch someone else’s code. If you found something in a component we recommended, we still want to know, because that changes what we recommend.

#What we commit to

stageour commitment
acknowledgement of your report2 working days
first assessment, confirmed or not5 working days
patch for a confirmed critical issue in our plugin7 days from confirmation
patch for a confirmed high or medium issuenext scheduled release
public advisory after the patch shipswithin 14 days

For a critical issue, if a patch cannot ship inside those 7 days, we will pull the plugin from distribution rather than leave a known hole in circulation, and we will tell you that is what we did.

The clock starts when we receive your report, not when the issue was introduced. If we go quiet for more than 10 working days without explaining why, treat that as a failure on our side and escalate to the second contact listed in our security.txt.

#When we cannot fix it in time

Sometimes a fix is not ready, or it is ready but breaks something that would hurt users more than the vulnerability does. In that case we publish a workaround and say why the fix is late. What we will not do is stay silent and hope the finder loses interest.

If you have a disclosure deadline, tell us in the first message. We will work to it or negotiate it openly. We do not ask for indefinite embargoes.

#Safe harbour

If you follow the rules below, we will not pursue or support legal action against you over the research, and we will say so in writing if you need it.

Test only against your own installation, or against a site you are explicitly authorised to test. Do not run denial-of-service tests. Do not send spam or bulk messages. Do not use social engineering against our people, our clients or our suppliers. Do not access, modify, exfiltrate or retain data that belongs to anyone else, and stop the moment you have enough to prove the issue.

If you accidentally access someone else’s data, stop, do not save it, and tell us what happened in the report. We would rather hear it from you.

#Credit, not cash

We run no bug bounty and pay no rewards. We are a small company and we would rather be honest about that than advertise a programme we cannot fund.

What we do offer: we credit reporters by name or handle in the release notes and in the advisory, if they want the credit, and we will confirm in writing that a report was valid and what we did about it. For a researcher building a track record, that written confirmation is usually the thing that matters.

#What we publish about our own plugins

Two commitments that follow from how the plugin ecosystem actually behaves. We measured the WordPress.org directory in August 2026 and found that more than half of all listed plugins had received no update in two years, almost always without any announcement.

So: when we stop maintaining a plugin, we will say so on its page and in a final release, rather than letting it go quiet. And when we ship a security release, the changelog will say that it is a security release, so anyone tracking our plugins can tell the difference between a fix and a feature.

#For clients under regulatory obligations

If you operate under NIS2 or the Polish national cybersecurity act and you use a plugin we publish, you may need to document us as a supplier in your ICT supply chain. This page, plus the timelines above, is the document to reference. Ask us and we will confirm the details in writing on company letterhead, including the versions you run and when they were last updated.

We are not able to file incident notifications to authorities on your behalf. That obligation sits with the covered entity, not with its supplier. We can supply the technical detail you need for your own filing, and we will do it inside your reporting window if you tell us what that window is.

#Contact

Last verified: 11 August 2026.

Recommendations from LinkedIn

Recommendations and reviews of working with WPPoland

Selected recommendations from WordPress, WordCamp and e-commerce leaders - with a focus on delivery on time, technical depth, and a business-driven approach to WordPress development.

Karolina Czapla

Karolina Czapla

Marketing Strategist, Performance & Digital Strategy

“Working with Mariusz on WordCamp has shown me how rare it is to combine deep technical skill with genuine leadership. He plans, coordinates and delivers with precision, while giving the team space to grow and contribute....”

Co‑organiser, WordCamp Gdynia 2024 & 2025

Argert Boja

Argert Boja

Senior Full‑Stack Developer

“Mariusz is the teammate everyone hopes for: strong full‑stack WordPress skills, clear explanations and a positive attitude even under pressure. He moves easily between custom plugins, performance work and Gutenberg layou...”

Worked alongside Mariusz on WordPress projects

Daniel Blossfeld

Daniel Blossfeld

Process Optimization & Digitalization Consultant

“I had the pleasure of working with Mariusz for almost three years. During that time, his WordPress development skills proved invaluable across a range of projects, from website builds to online member areas and even Shop...”

Mariusz was his client for WordPress work

Jessica Di Pasquale

Jessica Di Pasquale

Leading SEO initiatives with data-driven growth strategies.

“Mariusz is a very skilled, patient and expert guy. Always ready to help and to fix errors, I really appreciated working with him. He is such a great colleague!”

Managed Mariusz directly

Belinda Koch

Belinda Koch

Web-Tracking Analyst at TUI

“Mariusz is a great person to work with. He is extremely motivated to learn new things and share his knowledge, and is very knowledgeable on a wide range of topics. We worked together on digital analytics and tracking top...”

Worked with Mariusz on digital analytics and tracking topics

Paweł Lewczuk

Paweł Lewczuk

Front-end developer, WordPress developer

“I collaborated with Mariusz on several projects and our cooperation was always exemplary. I believe there are many more joint projects ahead of us. Highly recommended!”

Mariusz was Paweł's client

Service FAQ

Frequently Asked Questions

Questions about scope, delivery, pricing, and execution quality.

SEO-readyGEO-readyAEO-ready5 Q&A
Where do I report a vulnerability?#
Email [email protected] with the affected URL or plugin slug, the version, and enough detail to reproduce the issue. The same address is listed in our security.txt. You do not need to encrypt the report, though we will move to an encrypted channel if the finding warrants it.
How fast do you respond?#
We acknowledge a report within 2 working days and give a first assessment within 5. For a confirmed critical vulnerability in a plugin we publish, we ship a patch or pull the plugin from distribution within 7 days of confirmation. If we cannot make that, we say so and publish a workaround instead of going quiet.
What is in scope?#
The websites wppoland.com and plogins.com, and every plugin published under the plogins name, whether from the WordPress.org directory or from our own distribution. Third-party plugins we merely install for clients are out of scope; report those to their authors.
Do you pay for reports?#
No. We run no bug bounty and pay no rewards. We do credit reporters by name or handle if they want it, and we will confirm in writing that a report was valid, which is often what a researcher actually needs.
What are the rules for testing?#
Test only against your own installation or against a site you are authorised to test. Do not run denial of service, do not send spam, do not use social engineering against our people or clients, and do not access, modify or retain data belonging to anyone else. Stop as soon as you have proof and report it.

Need an FAQ tailored to your industry and market? We can build one aligned with your business goals.

Let’s discuss

Related Articles

Poland's NIS2 act and WordPress providers

Poland's NIS2 implementation has applied since 3 April 2026. Its definition of a managed service provider covers remote administration, so it describes anyone who maintains someone else's WordPress. What the text says, and what it does not.