Skip to content

Latest commit

 

History

History
40 lines (32 loc) · 1.74 KB

SECURITY.md

File metadata and controls

40 lines (32 loc) · 1.74 KB

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in the WP Ingresso plugin, please follow these steps:

  1. Contact us via [email protected].
  2. Provide detailed information about the vulnerability, including:
    • Steps to reproduce the issue.
    • The version of the plugin you're using.
    • Any relevant logs or screenshots.
  3. Please do not disclose the vulnerability publicly until we have addressed it and released a patch.

Response Times

We aim to:

  • Acknowledge your report within 48 hours.
  • Provide an initial assessment within 5 business days.
  • Release a fix or mitigation within 90 days, depending on the severity and complexity of the issue.

Supported Versions

The following versions of WP Ingresso are actively maintained and receive security updates:

Version Supported
1.x.x ✅ Yes

Security Best Practices

To ensure the safe use of the WP Ingresso plugin:

  1. Always keep the plugin updated to the latest version.
  2. Use the plugin in a secure WordPress environment, with:
    • The latest version of WordPress.
    • Properly configured server permissions.
  3. Regularly audit your site and third-party plugins for vulnerabilities.

External Dependencies

This plugin relies on external libraries and APIs (e.g., the Ingresso.com API). Please ensure that:

  • Your API keys and/or credentials are stored securely.
  • You monitor any changes in the terms or functionality of these external services.

Feedback and Improvements

We welcome feedback on how we can improve the security of WP Ingresso. Please feel free to reach out with suggestions or concerns.