# Security Policy for Terms and Conditions Popup on User Login

Thank you for helping keep our users safe. This document explains how to report vulnerabilities and how we handle them.

## Supported Versions

We provide security updates for the latest major version of the plugin.

| Version | Supported |
|--------:|:---------:|
|  **2.1.0** | ✅ |
|  older majors       | ❌ (please upgrade) |

> We follow semantic versioning. Security fixes are released as x.y.z patch releases when possible.

## How to Report a Vulnerability

- **Primary**: Report privately via **Patchstack mVDP** (preferred)  
  👉 https://patchstack.com/database/vdp/6a7a950b-4604-4e38-8556-c4a57d72ceec

- **Fallback**: Email **security@matyus.me** 

Please include:
- A clear description and impact
- Steps to reproduce / PoC
- Affected version(s) and environment
- Suggested fix (if you have one)

**Please do not** open public GitHub issues for security reports.

## Communication & Timelines

We aim to:
- **Acknowledge** your report within **48 hours**
- **Triage & assess severity** (CVSS) within **5 business days**
- **Fix or provide mitigation** within **14–30 days** (severity-dependent)
- **Coordinate disclosure** after a fix is available and users can update

If a fix needs more than 30 days, we’ll provide status updates at least weekly.

## Scope

In scope:
- This plugin’s codebase and update mechanisms
- WordPress admin screens, AJAX actions, REST endpoints, and hooks used by this plugin

Out of scope:
- WordPress core, other plugins/themes, hosting environments, or third-party services
- DoS/volumetric attacks, social engineering, physical attacks

## Testing Guidelines

✅ Allowed
- Local proof-of-concepts
- Non-destructive testing on your own sites

🚫 Not allowed
- Tests that disrupt production sites you don’t own
- Automated scans against third-party sites without consent
- Accessing personal data of real users

## Disclosure

We follow **coordinated disclosure**. After a fix:
- We publish release notes/changelog with **Security** section and **minimum safe version**
- Patchstack (and other databases) may publish advisories referencing the fixed version

## Credits / Recognition

We’re happy to thank researchers in release notes and on our site. If you prefer to remain anonymous, just say so.

## Bounties

We do **not** currently offer monetary bounties. Responsible disclosure recognition only.

## Contact

- Patchstack mVDP: <YOUR_PATCHSTACK_PROJECT_LINK>
- Email: security@<your-domain>.com
- Project: https://wordpress.org/plugins/terms-popup-on-user-login/
