PluginProbe
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages / 3.3.9
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages v3.3.9
3.4.1 3.4.0 3.3.9 3.3.8 3.3.7 3.3.6 3.3.5 3.3.4 3.3.3 3.3.2 3.3.1 2.2.0 2.2.1 2.2.2 2.2.3 2.2.4 2.2.5 2.2.6 2.2.7 2.2.8 2.2.9 2.3.0 2.3.1 2.3.2 2.3.3 All 194 releases
convertkit / SECURITY.md

SECURITY.md in Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages 3.3.9, at SECURITY.md

32 lines 1.4 KB
No matching file
Up and down to move Enter to open Esc to close
Raw Download Zip
1 # Security Policy
2
3 This security policy applies to public projects under the [](https://github.com/kitKit organization](https://github.com/kit](https://github.com/kit) on GitHub.
4
5 ## Reporting a Vulnerability
6
7 If you discover a security vulnerability, please report via any of the below:
8
9 - [](https://kit.com/report-vulnerabilityKit](https://kit.com/report-vulnerability](https://kit.com/report-vulnerability)
10 - [](https://patchstack.com/database/vdp/1010ebe1-02b2-4144-8297-b8cddba0ce7dPatchStack](https://patchstack.com/database/vdp/1010ebe1-02b2-4144-8297-b8cddba0ce7d](https://patchstack.com/database/vdp/1010ebe1-02b2-4144-8297-b8cddba0ce7d)
11 - [](https://github.com/Kit/convertkit-wordpress/security/advisoriesGitHub](https://github.com/Kit/convertkit-wordpress/security/advisories](https://github.com/Kit/convertkit-wordpress/security/advisories)
12 - [](mailto:security@kit.comEmail](mailto:security@kit.com](mailto:security@kit.com)
13
14 Please do **not** report security issues publicly via GitHub issues or discussions. Security reports sent via the above channels be acknowledged within 48 hours.
15
16 ## Security Disclosure Process
17
18 When reporting a security vulnerability, please include:
19
20 1. **Description** - A clear description of the vulnerability
21 2. **Impact** - What kind of vulnerability it is and who it impacts
22 3. **Reproduction** - Detailed steps to reproduce the issue
23 4. **Proof of Concept** - If applicable, include proof-of-concept code
24 5. **Suggested Fix** - If you have ideas for how to fix the issue
25
26 ## Security Response Timeline
27
28 - **Initial Response**: Within 48 hours of receiving the report
29 - **Investigation**: We will investigate and validate the reported vulnerability
30 - **Fix Development**: Development of a patch or mitigation strategy
31 - **Release**: Coordinated disclosure and release of security update
32 - **Public Disclosure**: After users have had time to upgrade