Reporting a vulnerability
How to tell us about a security problem in the platform or the worker, privately.
If you believe you have found a security problem in WP Octo — the platform, the worker plugin, or the way the two talk — please tell us privately rather than in a public issue.
Email: [email protected], with Security in the subject.
Include what you found, how to reproduce it, and which site or workspace it concerns if it is specific to one. If your report involves a customer's site, do not include that site's data; a description of the shape of the problem is enough.
What we ask
- Give us reasonable time to fix a problem before you describe it publicly.
- Do not access, change or delete data that is not yours while investigating. Reproduce against a site or workspace you control.
- Do not run scans or probes against managed sites; they belong to customers, and a firewall on their host will read it as an attack.
What we do
We acknowledge the report, tell you what we found, fix what needs fixing, and tell you when it is out. Fixes to the worker reach sites through the normal staged rollout; fixes to the platform go out with the next update. The two changelogs — application and worker plugin — record what shipped.