We take the security of AssetDrips seriously — it runs in wp-admin and can modify and delete media files, so we treat reports with priority.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report privately using one of:
- GitHub's private vulnerability reporting (preferred), or
- email security@codedrips.com.
Please include:
- A description of the issue and its impact.
- Steps to reproduce (proof-of-concept if possible).
- Affected version(s), and your WordPress/PHP environment.
- Any suggested remediation.
- We aim to acknowledge a report within 3 business days.
- We will keep you updated as we investigate and work on a fix.
- We will credit you in the release notes when the fix ships, unless you prefer to remain anonymous.
Please give us a reasonable opportunity to release a fix before any public disclosure. Thank you for helping keep AssetDrips and its users safe.
AssetDrips is pre-1.0 and under active development. Security fixes are applied to the latest released version. We recommend always running the most recent release.