Skip to content

Security: matthummel-pa/tocflow

Security

SECURITY.md

Security policy

Supported versions

Version Supported
1.x Yes
0.1.x No

Reporting a vulnerability

Please do not open a public GitHub issue for a security report.

Email matt@matthummel.com with:

  • WordPress and PHP versions
  • TOCflow version
  • A clear description and, if possible, steps to reproduce
  • Whether you plan to disclose after a fix (we will credit you if you want)

You should receive an acknowledgement within 7 days. Fixes for confirmed issues ship in a patch release as soon as they are ready.

This plugin does not call remote APIs and does not store personal data beyond normal WordPress options (tocflow_settings) and an optional per-user welcome-dismissal flag. See PRIVACY.md.

There aren't any published security advisories