Skip to Main Content
Compliance & Security
Last updated: June 20, 2026

Security & Vulnerability Disclosure Policy

We take the security of headless WordPress configurations seriously. This policy defines how we support security updates and handle vulnerability reports.

1. Supported Versions

We actively patch the current major version release of the DK Headless API plugin. Legacy versions may not receive security fixes, and upgrading to the latest release is highly recommended.

2. Responsible Disclosure

If you locate a security vulnerability, please contact security@digitizedkosmos.com directly. Do not open public GitHub issues or social media threads. We will verify reports, assign CVE indicators, and release patches within 72 hours.

3. Security Update Policy

When security patches are merged, notices are dispatched to waitlist subscribers and published to our official changelog. We recommend enabling automated plugin updates inside WordPress admin.