Security & coordinated disclosure.
Security & coordinated disclosure policy
Last updated: 26 August 2026
We welcome reports about security problems in WPChangeSync and in the websites we run for it. You do not need an account, a bug-bounty profile, or a formal write-up — a clear description is enough.
Email: security@wpchangesync.com
Helpful to include, when you have it
- what the issue is, and which version of WPChangeSync it affects;
- how to reproduce it (steps, a proof of concept, or a short video);
- what an attacker could achieve with it;
- whether you believe it is already being exploited in the wild;
- how you would like to be credited, if the report leads to a fix.
If you would rather not use email, any contact route on wpchangesync.com reaches us — say only that you have a security report and we will reply with a private channel. Please do not put working exploit details in a public forum, GitHub issue, or support ticket.
What we commit to
- Acknowledgement within 3 working days. A human reply, not an auto-responder.
- An assessment within 10 working days, telling you whether we consider the report valid, how severe we think it is, and what we plan to do.
- Progress updates at least every 14 days while the issue is open.
- A fix released as fast as the severity warrants. Critical issues are handled ahead of all other work.
- Credit where you want it. We name reporters in the release notes unless you prefer to stay anonymous.
- No legal action against good-faith research. See safe harbour below.
We do not currently run a paid bug-bounty programme. We say so plainly rather than implying a reward that does not exist.
What we ask of you
- Give us a reasonable chance to fix the issue before publishing. 90 days is our default disclosure window; if a fix is taking longer we will tell you why, and we are happy to agree a different timeline with you.
- Work only against your own installation or a test site. Do not access, modify, or download other people's data.
- Do not degrade our service or our customers' sites: no denial-of-service testing, no spam, no brute-forcing live logins, no social engineering of our customers or suppliers.
- Do not use an issue you find to gain further access than is needed to demonstrate it.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised. We will not pursue legal action against you, and if a third party does so over research that followed this policy, we will make clear that it was authorised.
If you are unsure whether something is in scope or acceptable, ask first at security@wpchangesync.com. Asking never counts against you.
Scope
In scope: the WPChangeSync plugin (all released versions, free and paid), its update and licensing endpoints, and the wpchangesync.com website.
Out of scope: third-party services we use but do not operate (our payment processor, hosting control panels, WordPress core, other people's plugins). If your finding is in one of those, we will happily help you route it to the right party.
Reports about our customers' websites are always welcome, but please send them to us rather than to the site owner, so we can coordinate the fix.
What we do with your report
We assess it, fix what needs fixing, and release an update. Where a fix matters to users, we describe the issue in the release notes once the update is available — enough for people to judge urgency, not enough to hand out a working exploit before others have patched.
If a vulnerability in WPChangeSync turns out to be actively exploited, or we suffer a severe security incident affecting the product, EU law (the Cyber Resilience Act) requires us to report it to the authorities within 24 hours, and to inform affected users about the issue and what they should do. We will do both, and we will not delay telling our users in order to look better.
Keeping your own installation safe
- Run the current version — updates are where security fixes ship.
- Keep WordPress core, PHP, and your other plugins current too; most incidents we see in the wild start somewhere other than the plugin under discussion.
- Restrict administrator accounts to people who genuinely need them, and enable two-factor authentication on them.
This policy applies to WPChangeSync, operated by Alterview, Hoogeveen, the Netherlands.