Skip to content

Security: ClassicPress/ClassicPress

SECURITY.md

Security Policy

ClassicPress is an open-source publishing platform forked from WordPress. The ClassicPress Core Team believes in Responsible Disclosure and encourage alerting the security team immediately and privately of any potential vulnerabilities.

Supported Versions

ClassicPress follows SemVer versioning. Security vulnerabilities will be considered for the most recent minor version in the current major branch.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues, the ClassicPress forums, Zulip or any other publicly accessible channel.

Instead, please use GitHub's private vulnerability reporting: https://github.com/ClassicPress/ClassicPress/security/advisories/new

Or email us at [email protected]

We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 90 days.

Disclosure Policy

We follow coordinated disclosure. Once a fix is released, we'll publish a GitHub Security Advisory (GHSA) with credit to the reporter (unless they prefer to stay anonymous).

Learn more about advisories related to ClassicPress/ClassicPress in the GitHub Advisory Database