Vulnerability disclosure

If you have found a security vulnerability in a CoreDigify product, the portal or one of the sites we manage — thank you for choosing the responsible route. This page describes how to report and what to expect from us.

Scope

We accept reports about:

  • the CoreDigify WordPress plugin and its modules (bricks)
  • CDDS themes
  • the CoreDigify PrestaShop module
  • the client portal my.coredigify.com and its API
  • this website, coredigify.com
  • client sites under our management (we will also pass the report to the site owner)

How to report

Write to us by e-mail or use the contact form with the “Security report” topic:

What to include

  • The affected product or site and, if known, the version
  • Steps to reproduce the vulnerability (PoC if you have one)
  • Observed and expected behaviour
  • Your contact details for a reply (a pseudonym is fine)

What we commit to

  • Acknowledge receipt within 3 working days
  • Keep you informed about the assessment outcome and the fix
  • Handle actively exploited vulnerabilities within the deadlines of Article 14 of the EU Cyber Resilience Act (CRA)
  • Credit you publicly as the discoverer after the fix ships, if you wish

Good-faith research

We will not pursue legal action against good-faith security research that follows these rules. Please: do not access or download other people's data beyond what is needed to demonstrate the vulnerability; do not run denial-of-service tests, send spam or use social engineering; do not disclose the vulnerability publicly before we have fixed it or 90 days have passed since your report.

Security support periods

For our products (the CoreDigify WordPress plugin and its modules, CDDS themes, the PrestaShop module) we provide security updates for 5 years from each release. Fixes ship as free updates to the current version through the product's built-in update channel; we do not patch older versions separately. Products are provided solely as part of the CoreDigify managed service.

security.txt

Machine-readable reporting information is available in RFC 9116 format: coredigify.com/.well-known/security.txt