Security and Vulnerability Reporting
Last updated: September 2, 2026
AIVOW – AI Disclosure Manager takes security reports seriously. This page explains how to report a suspected security vulnerability privately and what information helps us investigate it.
This process is intended for security vulnerabilities. For general product questions, configuration problems, compatibility issues, and non-security defects, please use the Support page or Report a Bug page.
Report a suspected vulnerability
Send security reports to [email protected].
Use a subject line beginning with:
[AIVOW Security] Brief description of the issue
Please report suspected vulnerabilities privately. Do not publish vulnerability details through public issue trackers, forums, reviews, social media, or other public channels before we have had a reasonable opportunity to investigate and, where appropriate, address the issue.
What to include
Please include as much of the following information as reasonably possible:
- The affected product, component, page, or feature.
- The exact AIVOW Lite version.
- Where the affected copy was downloaded.
- Relevant WordPress, PHP, WooCommerce, browser, server, or hosting versions.
- A clear description of the suspected vulnerability and its potential impact.
- Reproducible steps using the smallest practical proof of concept.
- Whether the issue was reproduced with the latest official release.
- Relevant screenshots, logs, or error messages after removing secrets and unnecessary personal data.
- Any suggested remediation, if available.
- A contact email address if you are willing to answer follow-up questions.
Plain-text reports are preferred. Please do not send active malicious payloads or executable attachments unless we specifically request them through an agreed method.
Do not send credentials or sensitive data
Do not send:
- WordPress administrator credentials or passwords.
- API keys, authentication tokens, private keys, or recovery codes.
- Payment card or financial account information.
- Customer records or full database exports.
- Private website files or confidential business information.
- Personal data that is not necessary to explain the issue.
- Unredacted logs or screenshots containing secrets or personal information.
If sensitive information appears in supporting material, redact it before sending.
Testing expectations
Only test systems, websites, accounts, and data that you own or are explicitly authorized to test.
When investigating a suspected vulnerability:
- Use the minimum testing necessary to demonstrate the issue.
- Stop testing after the issue has been reproduced.
- Do not disrupt service availability or degrade website performance.
- Do not perform denial-of-service testing or high-volume automated scanning.
- Do not use social engineering, phishing, spam, malware, or persistence mechanisms.
- Do not alter, delete, corrupt, or exfiltrate data.
- Do not access more data than is necessary to demonstrate the issue.
- Do not test third-party services without their authorization.
- Comply with applicable laws and the rights of other people.
If you unexpectedly access private data, stop immediately. Do not copy, retain, use, or disclose the data, and report the incident privately as soon as reasonably possible.
This policy does not grant authorization to access or test systems, accounts, or data that you do not own or have explicit permission to test.
Scope
Relevant reports may include vulnerabilities affecting:
- The latest supported official release of AIVOW Lite.
- Official AIVOW website functionality where the issue is reasonably attributable to our own code or configuration.
- Official AIVOW Pro releases after they become publicly available.
Reports involving outdated, unofficial, or materially modified copies may not be reproducible or actionable.
Third-party products and services
AIVOW Lite operates within a wider WordPress environment. WordPress core, WooCommerce, other plugins, themes, hosting providers, Cloudflare services, browsers, AI providers, and other third-party products operate independently.
A vulnerability that exists only in a third-party product should be reported directly to that product’s developer or security contact.
Product behavior that is not a security boundary
The AIVOW Lite Interaction Gate requests acknowledgement before revealing selected content. It is not authentication, authorization, access control, a paywall, or secure protection for confidential or sensitive content.
The presence of gated content in the delivered page source or browser-accessible markup is therefore expected product behavior and is not, by itself, a security vulnerability.
How reports are handled
We will review credible security reports on a best-effort basis and may request additional information to reproduce or understand the issue.
Response, investigation, remediation, and release times depend on the severity, reproducibility, technical complexity, affected components, and availability of a safe fix. We do not guarantee a particular response or remediation deadline.
Please keep vulnerability details confidential while the report is being investigated. Any coordinated public disclosure timing should be discussed case by case.
Submitting a report does not guarantee payment, a bug bounty, public credit, employment, or any other reward. No bug bounty program is currently offered.
This page does not create a contract, legal safe harbor, immunity, agency relationship, or authorization to perform testing that would otherwise be unlawful or unauthorized.
Official downloads and integrity information
Download AIVOW Lite only from the official AIVOW website or its official WordPress.org listing.
Where a filename, version number, or checksum is published, you may use it to verify the downloaded file. Report unexpected file differences privately before installing or distributing the file.
General security recommendations
No software can be guaranteed to be free from every vulnerability. Website administrators should:
- Keep WordPress, PHP, themes, and plugins updated.
- Install software only from trusted sources.
- Use unique passwords and appropriate administrator access controls.
- Maintain tested backups.
- Test important updates in a staging environment where practical.
- Grant users only the permissions they need.
- Remove unused themes and plugins.
Related information
Contact
Security reports and related questions: