Security

Vulnerability Disclosure Policy

Last Updated: 21 August 2026

We appreciate the security research community’s efforts in helping us maintain the security of our product and our users.

This policy describes how to report security vulnerabilities to us and what to expect when you do.

Scope

This policy applies to the following product: BricksExtras (WordPress Plugin)

How to Report a Vulnerability

Please report security vulnerabilities by email to: security@bricksextras.com

Include in your report:

  1. Description of the vulnerability
  2. Steps to reproduce the issue
  3. Potential impact and severity assessment
  4. Any proof-of-concept code (if applicable)
  5. Your suggested fix (if any)

What to Expect

  1. Acknowledgment: We will acknowledge your report within 1 business day
  2. Assessment: We will assess the vulnerability and determine its severity
  3. Fix: We aim to develop and test a fix within 3 business days
  4. Disclosure: We will coordinate public disclosure with you after the fix is released

Safe Harbor

We consider security research conducted in accordance with this policy to be:

  • Authorized and lawful
  • Not subject to legal action by us
  • Helpful and appreciated

We will not pursue legal action against researchers who:

  • Follow this disclosure policy
  • Make a good faith effort to avoid privacy violations, data destruction, and service disruption
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate the issue

Contact

  • Security Email: security@bricksextras.com
  • Website: https://bricksextras.com
  • Organization: WPLIT PTY LTD