Security & Vulnerability Disclosure Policy
We take the security of headless WordPress configurations seriously. This policy defines how we support security updates and handle vulnerability reports.
1. Supported Versions
We actively patch the current major version release of the DK Headless API plugin. Legacy versions may not receive security fixes, and upgrading to the latest release is highly recommended.
2. Responsible Disclosure
If you locate a security vulnerability, please contact security@digitizedkosmos.com directly. Do not open public GitHub issues or social media threads. We will verify reports, assign CVE indicators, and release patches within 72 hours.
3. Security Update Policy
When security patches are merged, notices are dispatched to waitlist subscribers and published to our official changelog. We recommend enabling automated plugin updates inside WordPress admin.