Responsible Disclosure: Help Us Protect Aegisify Customers
Aegisify supports responsible security research that helps protect its products, customers, and WordPress environments. Potential vulnerabilities in Aegisify Audit, the Aegisify Agent, or any Aegisify plugin can be reported privately for safe investigation and coordinated remediation.
The disclosure process provides a clear path for authorized testing and confidential reporting while protecting customer data, service availability, and platform trust.

Aegisify Facts & Truth
Responsible Security Disclosure
Aegisify welcomes responsible security research that helps us strengthen our WordPress products, SaaS platform, Agent connections, and customer data protections. If you believe you have discovered a security vulnerability, please report it privately so our team can investigate the issue and take appropriate action.
This disclosure process is intended for security researchers, WordPress professionals, developers, customers, and technology partners who identify a potential weakness in an Aegisify-owned product or service.
Security Issues We Want to Hear About
Please contact Aegisify when you discover a vulnerability that may affect the confidentiality, integrity, availability, authentication, authorization, or secure operation of an Aegisify product or service.
Examples of relevant security findings include:
- Authentication or authorization bypasses
- Cross-site scripting, SQL injection, request forgery, or insecure direct object reference vulnerabilities
- Exposure of sensitive account, scan, telemetry, or security data
- Weaknesses involving Agent authentication, domain connections, security keys, or telemetry access
- Vulnerabilities affecting scan execution, report generation, dashboards, account boundaries, or SaaS workflows
- Security issues involving WordPress audit results, plugin or theme intelligence, optional logs, code-analysis findings, externally observed evidence, or AI-assisted report data
Research Must Be Safe and Authorized
Security research should demonstrate the issue using the minimum access and activity needed to confirm that a vulnerability exists. Testing must remain limited to Aegisify systems you are authorized to evaluate and must not place customers, customer information, service availability, or third-party systems at risk.
Please do not:
- Access, copy, download, modify, disclose, or delete customer data
- Perform denial-of-service, high-volume load, spam, or destructive testing
- Use phishing, social engineering, credential theft, or physical attacks
- Install malware or establish persistent access to an Aegisify or customer environment
- Test a customer’s WordPress website without the owner’s written authorization
- Continue testing after sensitive information becomes visible
- Publicly disclose an unresolved vulnerability before Aegisify has had a reasonable opportunity to investigate and respond
If you unexpectedly encounter customer information or other sensitive data, stop testing, do not retain or share the information, and notify Aegisify immediately.
How to Submit a Security Report
Send your report privately to support@aegisify.com with Security Report in the subject line.
A complete report helps our team reproduce, evaluate, and prioritize the issue. Please include:
- The affected Aegisify product, feature, endpoint, or URL
- A clear description of the suspected vulnerability
- Safe and repeatable steps that demonstrate the issue
- The potential security or business impact
- Relevant product versions, browser details, WordPress versions, or environment information
- Screenshots, request details, or redacted logs when they are necessary to explain the finding
- Your preferred contact information for follow-up questions
Do not send passwords, live security keys, complete access tokens, payment information, or unredacted customer data with your report.
What Happens After a Report Is Submitted
Aegisify will review the information provided, evaluate whether the issue can be reproduced, assess its potential impact, and determine the appropriate response. We may contact the reporter for additional technical details or validation.
The time needed to investigate and address a report can vary based on its severity, technical complexity, affected products, required testing, and potential customer impact. We ask researchers to keep the report confidential while the investigation and remediation process is underway.
Good-Faith Security Research
Aegisify appreciates researchers who act in good faith, respect customer privacy, avoid service disruption, remain within authorized testing boundaries, and disclose findings privately through this process.
When research follows these requirements, Aegisify intends to work constructively with the reporter to understand the issue and improve the affected product or service. Activities involving unauthorized access, customer systems, privacy violations, data misuse, extortion, or destructive testing are not covered by this policy.
Bounties, Payments, and Recognition
Submitting a security report does not automatically qualify the reporter for a bounty, payment, reward, or public recognition. A reward is available only when Aegisify has an active written bounty program and the report satisfies that program’s eligibility requirements.
Responsible reports remain valuable even when no financial reward is offered. Recognition, when appropriate, will be discussed with the researcher and will not be published without permission.
Protecting Trust Across the Aegisify Platform
Aegisify brings together WordPress security audit findings, Agent telemetry, plugin and theme intelligence, code-analysis signals, externally observed evidence, optional logs, risk prioritization, and AI-assisted analysis. Protecting these workflows is essential to the customers, agencies, ecommerce operators, developers, executives, and security teams that rely on Aegisify.
Responsible disclosure gives qualified researchers a clear path to report potential weaknesses while protecting customer privacy, system availability, and the integrity of the investigation.
Understand the Security Posture of Your WordPress Site
Aegisify Audit helps WordPress professionals, marketing teams, executives, and security architects bring plugin and theme risk, code-analysis findings, external exposure, configuration posture, optional logs, and AI-assisted prioritization into one organized security workflow.
See what matters, understand the potential impact, and give your team a clearer path from technical evidence to informed action.








