Security · Coordinated disclosure
Report a security issue responsibly.
Use a private channel, synthetic data, and the minimum testing needed to explain the issue.
Report privately
Use GitHub’s private Report a vulnerability workflow when available, or email jacob@codeprint.io. Do not publish exploit details in an issue.
What to include
- Affected version and Free or Premium package
- WordPress, WooCommerce, PHP, and checkout-surface versions
- A concise impact statement
- Safe reproduction steps using synthetic data
- Whether authentication or an external service is required
Rules of engagement
- Test only systems and data you own or are authorized to test
- Use a disposable local or sandbox environment
- Do not run real payment transactions or use real card data
- Do not perform denial of service, destructive actions, persistence, social engineering, or privacy violations
- Stop after collecting enough evidence and allow reasonable remediation time
Sensitive data
Never send card data, payment payloads, customer records, production database exports, cookies, passwords, secret keys, tokens, or license keys. Redact store and shopper identity.
Good-faith research
Codeprint intends to investigate good-faith reports, coordinate remediation and disclosure, and credit reporters who request attribution. This policy is not authorization to violate law, third-party terms, or another person’s rights.
Version 1.0.0 · Available on WordPress.org
Put a control between checkout abuse and your payment gateway.
Install the complete Free edition from the official WordPress.org Plugin Directory. New installations begin safely in Observe Mode.