Security policy
If you think you have found a security problem with this site, I would rather hear about it than not. This page explains how to tell me and what happens next.
How to report
Email [email protected]. Include a clear description of the issue, the steps to reproduce it, and any screenshots or proof-of-concept code that helps me confirm it. Plain text is fine — there is no form to fill in and no bug bounty platform in the way.
What to report
Authentication or authorization flaws
Cross-site scripting (XSS) or injection vulnerabilities
Sensitive data exposure
Anything that could allow unauthorized access to data or site functionality
Out of scope
Denial of service attacks
Spam or social engineering
Publicly disclosed issues in third-party plugins or themes
Automated scanner output with no proof of exploitability
What you can expect
An acknowledgement that your report arrived
Updates as I investigate and fix the issue
Credit for the discovery, if you want it
Safe harbor
I will not pursue legal action against researchers who find and report vulnerabilities in good faith, provided they do not access, modify or delete data belonging to anyone else, and do not disrupt normal operation of the site.
Spam protection
Forms on this site are protected by Cloudflare Turnstile. When you submit a form, your interaction may be processed by Cloudflare under their Privacy Policy and Terms of Service.
A machine-readable version of this policy is published at /.well-known/security.txt.