Responsible Disclosure Policy
We take security seriously, and we welcome reports from security researchers and customers who find a potential vulnerability in WP Guard. This policy explains how to report an issue to us safely and what to expect.
Last updated: 29 July 2026
How to report
If you believe you have found a security vulnerability in the WP Guard website, plugin or service, please email us at support@wpguard.ai with the subject line “Security”. Include enough detail for us to reproduce the issue: what you found, where, and the steps to trigger it.
What we ask of you
- Give us a reasonable chance to investigate and fix the issue before you share it publicly.
- Do not access, change or delete data that is not yours, and do not degrade the service for others.
- Only test against your own account or websites, not those of other customers.
- Do not use social engineering, physical attacks, or denial of service testing.
What you can expect from us
- We will acknowledge your report and look into it.
- We will work to validate and fix confirmed issues, and keep you updated on progress.
- We will treat your report in good faith and will not pursue action against researchers who follow this policy.
Scope
This policy covers the WP Guard website and the services we operate. It does not authorise testing against third-party services, or against websites we host on behalf of customers without that customer’s permission.
Thank you
Responsible reports make the whole WordPress community safer. We appreciate the time researchers take to help us improve.