Skip to content

Security: AEO-God-Mode/aeo-god-mode

Security

SECURITY.md

Security Policy

We take security seriously. Thank you for helping keep AEO God Mode and its users safe.

Reporting a vulnerability

Please report suspected vulnerabilities privately by emailing security@aeogodmode.io.

Do NOT open a public GitHub issue, post in the WordPress.org support forum, or share the details on social media until we have confirmed a fix is available.

When you email us, please include:

  • A clear description of the issue
  • The plugin version affected
  • Steps to reproduce, including any proof-of-concept code or URLs
  • The impact you believe this has on a typical site
  • Whether you would like to be credited in the public disclosure

What to expect

  • Acknowledgement: within 3 business days
  • Initial assessment: within 7 business days
  • Fix or status update: within 30 days for confirmed issues

If we confirm the issue, we will:

  1. Develop and test a fix on a private branch
  2. Release a patched version through WordPress.org
  3. Publish a security advisory on this repository once a fix is publicly available
  4. Credit you in the changelog and advisory if you wish

Supported versions

Only the latest released version of AEO God Mode receives security updates. Please update to the current release before reporting.

Out of scope

The following are not considered vulnerabilities for this project:

  • Issues affecting only end-of-life WordPress versions
  • Self-XSS that requires the victim to paste attacker-controlled code into their own browser console
  • Lack of HTTPS on a self-hosted demo site
  • Issues in third-party plugins or themes that are reproduced through AEO God Mode but caused elsewhere

Hall of thanks

Researchers who responsibly disclose valid issues are credited here in the changelog and the GitHub security advisory unless they prefer to remain anonymous.

There aren't any published security advisories