As a provider of security software, services, and research, we take security issues very seriously and strive to lead by example. We recognise the importance of collaboration between vendors, researchers, and customers and seek to improve the safety and security of the community as a whole through a coordinated disclosure process.
Contact the Wordfence Security Team by sending email to [email protected] in the following situations:
To ensure confidentiality, we encourage you to encrypt any sensitive information you send to us via email. We are equipped to receive messages encrypted using our public PGP key.
After your incident report is received, the appropriate personnel will contact you to follow-up. Wordfence attempts to acknowledge receipt to all submitted reports within seven days.
The [email protected] email address is intended ONLY for the purposes of reporting product or service security vulnerabilities. It is not for technical support. All content other than that specific to security vulnerabilities in our products or services will be dropped. For technical and customer support inquiries, please visit https://support.wordfence.com.
When the Wordfence Research Team finds a vulnerability in another vendor’s product, or if a vulnerability affecting our plugin is disclosed to us, we take the following steps to address the issue. “Vendor” below may refer to us or to an external vendor.
All aspects of this process are subject to change without notice, and to case-by-case exceptions.