We build self-hosted software that runs on your own servers, so security matters to us as much as it does to you. If you believe you've found a vulnerability in one of our plugins or services, we want to hear from you — and we'll work with you to fix it quickly.
Email [email protected] with [SECURITY] in the subject line, or use our contact form and mark it as a security report. Please do not open a public issue, post to the WordPress.org forums, or disclose the details publicly until we've had a chance to release a fix.
To help us triage quickly, include where you can:
The following are in scope for disclosure:
jnkplugins.com and license.jnkplugins.com.Generally out of scope: volumetric or denial-of-service attacks, social engineering of our staff or customers, spam or content-injection via forms without a concrete security impact, missing best-practice headers with no demonstrated exploit, and automated scanner output without a working proof of concept.
We will not pursue or support legal action against researchers who report vulnerabilities in good faith, act within this policy, avoid privacy violations and service disruption, and give us a reasonable window to remediate before any public disclosure. If you're unsure whether an action is acceptable, ask us first.
Because our software is self-hosted, the most important thing you can do is keep your plugins and WordPress core up to date — security fixes ship through the normal update channel. Pro licenses continue to receive updates for the life of the license.
Security reports: [email protected]. For anything else, see our contact page.
Last updated: July 29, 2026.