Updated: August 2026

WP Ghost (formerly Hide My WP Ghost) is a security product, so we treat reports about our own code with the seriousness we ask of everyone else. This document is the coordinated vulnerability disclosure policy for the WP Ghost plugin, in both the free and the premium edition. It is published by MINBO QRE SRL (Company No. 37814865).

If you have found a security issue in WP Ghost, section 1 tells you where to send it and section 4 tells you what protection you have while you research it. If you believe an issue is already being exploited against live websites, read section 3 first.

1. Reporting a Vulnerability

Please do not open a public GitHub issue, a wordpress.org support topic, or a social media post for an unfixed vulnerability. Those channels are read by people who are not on our security team, and disclosure there puts every WP Ghost user at risk before a fix exists.

1.1 Preferred Route: Patchstack Managed VDP

WP Ghost participates in Patchstack’s managed Vulnerability Disclosure Program, which handles triage and researcher coordination:

1.2 Direct Route: Email

If you would rather contact us directly, or your report is time critical, email [email protected].

1.3 What to Include in Your Report

The more of this you can give us, the faster we can confirm and fix the issue:

  • The affected version, and the edition (free or premium)
  • The vulnerability class, and the component or file involved
  • Reproduction steps, ideally with a proof of concept
  • The privilege level required (unauthenticated, subscriber, administrator, and so on)
  • What an attacker gains
  • Your server environment, if it is relevant: server type, PHP version, multisite

2. What You Can Expect From Us

StageOur commitment
AcknowledgementWithin 48 hours (2 business days) of receiving your report
Triage and initial assessmentWithin 7 days, including whether we can reproduce it
Fix and releaseAs fast as severity warrants, up to 90 days
Coordinated disclosureAt release, or 90 days after the report, whichever is sooner

We will keep you updated as the fix progresses rather than going quiet, and we will credit you in the release notes unless you ask us not to.

If we need longer than 90 days for something genuinely complex, we will say so and agree a revised date with you rather than let the deadline pass in silence.

3. Actively Exploited Vulnerabilities

If you have evidence that a vulnerability in WP Ghost is being exploited in the wild, say so explicitly and prominently in your report, and use the direct email route in section 1.2 rather than waiting on the queue.

Active exploitation triggers regulatory notification obligations on our side with a 24-hour clock attached, so that detail changes what we have to do and how quickly we have to do it.

4. Safe Harbour

We will not pursue legal action against you, or ask anyone else to, for security research conducted in good faith under this policy. Good faith means:

  • Testing only against websites you own or have written permission to test
  • Not accessing, modifying, or destroying data belonging to anyone else
  • Not degrading service for other users: no denial of service, and no automated scanning that generates disruptive load
  • Giving us a reasonable opportunity to fix the issue before disclosing it publicly

If you are unsure whether something is in scope, ask first.

5. Scope

5.1 In Scope

Vulnerabilities in WP Ghost plugin code, in either edition: the paths and rewrite layer, firewall rules, brute force protection, two-factor authentication, temporary and magic logins, the logs, the admin interface, and the plugin’s own update mechanism.

5.2 Out of Scope

  • Vulnerabilities in WordPress core, in a hosting environment, or in another plugin or theme, unless WP Ghost is what makes them exploitable
  • Findings that require an administrator account to exploit, where an administrator could already achieve the same result through normal WordPress functionality
  • Missing hardening headers or configuration recommendations with no demonstrated impact
  • Reports produced entirely by an automated scanner with no verified exploitability
  • Social engineering of our staff or customers

5.3 Third-Party Components

Third-party components bundled with the plugin are listed in sbom.json. Report those upstream as well, but tell us too, because we are responsible for what we ship.

6. Supported Versions

Security updates are provided for 5 years from the date each version is placed on the market. In practice we ship security fixes on the current release line, so the reliable way to stay covered is to run the latest version.

  • WP Ghost Premium: current release line
  • WP Ghost (free, wordpress.org): current release line

7. Changes to This Security Policy

We may update this policy as our processes, obligations, or disclosure programme change. The date at the top of this page reflects the most recent revision. Reports submitted before a change are handled under the version of the policy that was published when they were submitted.

8. Contact Information

For security reports, use [email protected] or the Patchstack programme linked in section 1.1. For anything that is not a security report, please use our contact form.