Skip to content

Security: drewmt/lineweb-blocks

Security

SECURITY.md

Security policy

Supported releases

Security fixes are prepared for the latest published version of each Lineweb plugin. If a report also affects an older release, update guidance will be included where practical. WordPress, WooCommerce, and PHP must meet the minimum versions declared by the affected plugin.

Report a vulnerability privately

Do not open a public issue for a suspected vulnerability before a fix and coordinated disclosure are available.

Send the initial report through the Lineweb contact form and include:

  • the plugin name and affected version;
  • the WordPress, WooCommerce, and PHP versions used;
  • clear reproduction steps or a minimal proof of concept;
  • the security impact and required attacker permissions;
  • whether the issue is already public or known to another party.

Never include live credentials, personal data, customer orders, private keys, or a production database export. If sensitive diagnostic material is necessary, request a secure transfer method in the initial report.

What to expect

Lineweb will acknowledge a complete report, attempt to reproduce it on a supported release, assess its severity, and coordinate remediation and disclosure with the reporter. A narrowly scoped security fix and changelog entry will be published when disclosure is safe.

Good-faith research should use an installation you own or have explicit permission to test. Do not access third-party data, interrupt a live service, send unsolicited traffic, or use a discovered issue beyond the minimum needed to demonstrate impact.

There aren't any published security advisories