Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
# Security Policy

This security policy applies to public projects under the [Kit organization](https://github.com/kit) on GitHub.

## Reporting a Vulnerability

If you discover a security vulnerability, please report via any of the below:

- [Kit](https://kit.com/report-vulnerability)
- [GitHub](https://github.com/Kit/convertkit-wordpress-libraries/security/advisories)
- [Email](mailto:security@kit.com)

Please do **not** report security issues publicly via GitHub issues or discussions. Security reports sent via the above channels will be acknowledged within 48 hours.

## Security Disclosure Process

When reporting a security vulnerability, please include:

1. **Description** - A clear description of the vulnerability
2. **Impact** - What kind of vulnerability it is and who it impacts
3. **Reproduction** - Detailed steps to reproduce the issue
4. **Proof of Concept** - If applicable, include proof-of-concept code
5. **Suggested Fix** - If you have ideas for how to fix the issue

## Security Response Timeline

- **Initial Response**: Acknowledgement within 48 hours of receiving the report
- **Investigation**: Investigation and validation of the reported vulnerability
- **Fix Development**: Development of a patch or mitigation strategy
- **Release**: Coordinated disclosure and release of security update
- **Public Disclosure**: Public announcement after users have had time to upgrade