Last Updated: August 13, 2026
At RyanPlugins, we take the security of our WordPress and WooCommerce plugins seriously. We appreciate security researchers, customers, and users who responsibly report security vulnerabilities.
This Security Policy explains how to report security issues and how we handle vulnerability reports.
1. Reporting a Security Vulnerability
If you believe you have discovered a security vulnerability in a RyanPlugins product, please report it as soon as possible.
Security Email:
security@ryanplugins.net
Please do not publicly disclose the vulnerability before we have had an opportunity to investigate and address the issue.
Please include the following information:
- Plugin name
- Plugin version
- WordPress version
- WooCommerce version, if applicable
- PHP version, if relevant
- Description of the vulnerability
- Steps to reproduce the issue
- Potential security impact
- Proof of concept, if available
- Screenshots or logs, if applicable
Please avoid including sensitive customer information, payment information, passwords, API keys, or other confidential data in your report.
2. What We Consider a Security Vulnerability
Examples of security issues include:
- Authentication bypass
- Unauthorized access
- Privilege escalation
- SQL injection
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Remote code execution
- Sensitive information disclosure
- Insecure API endpoints
- Payment or transaction security vulnerabilities
- Exposure of credentials, tokens, or API keys
- Other issues that could compromise the security of a website or its users
Normal bugs, compatibility problems, feature requests, and general support questions should be submitted through our normal support channels rather than the security email.
3. Our Response Process
When we receive a security report, we will:
- Review and acknowledge the report.
- Investigate and validate the reported issue.
- Determine the severity and affected versions.
- Identify affected products and users where applicable.
- Develop and test a security fix.
- Release an updated version when appropriate.
- Notify affected users when necessary.
- Provide relevant information about the vulnerability and recommended mitigation steps.
For serious security issues, we may prioritize the security fix over our normal development and release schedule.
4. Security Updates
Security fixes may be released as plugin updates through the applicable distribution channels.
Users should keep RyanPlugins products, WordPress, WooCommerce, PHP, and other dependencies up to date.
When a security issue affects an older version, we may recommend upgrading to the latest available version.
5. Responsible Disclosure
We ask security researchers to practice responsible disclosure.
Please:
- Give us reasonable time to investigate and address the issue.
- Avoid accessing, modifying, deleting, or exposing other users’ data.
- Avoid disrupting websites or services.
- Avoid conducting denial-of-service attacks.
- Do not publicly disclose the vulnerability before coordinating with us.
- Do not use a vulnerability to access information beyond what is necessary to demonstrate the issue.
We appreciate responsible security research that helps us improve our products.
6. Actively Exploited Vulnerabilities and Severe Security Incidents
Where applicable, RyanPlugins will assess security incidents and vulnerabilities to determine whether additional reporting or notification obligations apply.
For software made available to users in the European Union, applicable requirements under the EU Cyber Resilience Act (CRA) may require reporting of certain actively exploited vulnerabilities or severe security incidents.
Where such requirements apply, we will follow the applicable reporting timelines and notify affected users as appropriate.
7. Security Contact
For security-related matters:
Email: security@ryanplugins.net
Subject: Security Vulnerability Report
Please use the security email specifically for security vulnerabilities and incidents.
8. Policy Updates
We may update this Security Policy from time to time to reflect changes to our products, security practices, applicable requirements, or industry standards.
The “Last Updated” date at the top of this page indicates when this policy was most recently updated.