# Security policy

## Reporting a vulnerability

Report a suspected vulnerability privately to `wordpress@320px.ru` with the
subject `[320px Site Audit security]`. Include the plugin version, WordPress and
PHP versions, a concise reproduction, the expected boundary, and the observed
result.

Do not send passwords, API keys, cookies, personal data, database dumps,
`wp-config.php`, `.env`, private keys, client files, or a complete production
report. Use a minimal synthetic fixture. If a sensitive attachment is genuinely
necessary, first ask for an agreed secure transfer method.

The 320px team aims to acknowledge a complete report within three working days
and provide an initial triage update within seven. Timing of a fix depends on
severity, reproducibility, compatibility risk, and coordinated-disclosure
needs. Please allow a reasonable remediation window before public disclosure.

## Supported versions

Security fixes are prepared for the newest released `0.1.x` line. Before the
first public directory release, the exact submitted build is the supported
candidate. After a fixed version is available, older affected builds may be
marked unsupported.

## Product security boundary

Site Audit is read-only with respect to the audited site. The full base report
is local and has no telemetry or hidden report transfer. Optional network
operations require a specific administrator action and disclosure. A security
report should identify which documented boundary was crossed; the full model is
also summarized in `readme.txt`.

The 320px team will validate reports factually, minimize retained reporter data,
coordinate a release and advisory where appropriate, and credit reporters only
with their explicit permission.
