The security of our websites and software products is essential to us and our customers. In spite of our care, procedures and best efforts it is possible that there are vulnerabilities in our websites or software products. If you find any, please tell us as soon as possible so we can fix it.

Scope:

You may check the following domains (including subdomains) for vulnerabilities:

You may test the following WordPress plugins for vulnerabilities:

If you want to test the Pro versions of the aforementioned plugins, you will have to buy a license through the respective websites.

We ask you to:

Report your findings by sending an e-mail to: [email protected]

Minimum requirements for a valid report

A report is only considered valid if it includes all of the following:

Theoretical findings, static analysis notes, and “this looks unsafe” reports without a working proof of concept are not vulnerabilities under this policy. Bulk or spray submissions may be held or closed without individual replies.

AI-assisted reports

We do not ban AI assistance, but we wish to know when it is being used. Do not submit unverified AI output.

Reports that appear to be unverified AI output (fabricated code paths, non-existent functions, generic vulnerability templates, or scanner dumps without human verification) will be closed without further triage. Repeated low-quality submissions may result in permanent exclusion from our bounty program.

Out of scope

The following are explicitly out of scope and will be closed without bounty consideration:

WordPress / plugin-specific

No / low security impact

Process / environment

The following is explicitly NOT allowed:

Doing any of these things without explicit prior written consent from us may result in a report to law enforcement and or legal action against you!

If you think you have found a vulnerability but feel you cannot produce proof of compromise without complying with the above restrictions, please contact us.

What you can expect from us:

What we do with vulnerabilities we find ourselves:

When we find vulnerabilities in software or websites we use, we will inform the responsible parties according to their responsible/coordinated vulnerability disclosure policy.

Bounties

Only reports of real vulnerabilities with proof that you personally can exploit them are eligible for rewards. We may reward those vulnerabilities with proof of compromise with monetary compensation, depending on the possible impact of the vulnerability. Eligibility and size of bounties are solely at our discretion. Out-of-scope reports are not eligible for rewards.

Please do not submit output from automated scanning tools or AI-generated reports unless you have personally verified the finding and included a working proof of concept.
Any time spent by us on invalid reports you make will limit any bounties you may receive for real vulnerabilities in the future!


Reporting data breaches

Your privacy and the confidentiality of you and your data is very important to us. In spite of the care we take protecting your data it is possible for information to leak. This is how we would handle such an event:

What we consider a data breach

A situation where we know or can reasonably suspect that unauthorized access to personal or business information entrusted to us has occurred

How we respond to a data breach

After finding out about the data breach, our highest priority is fixing the leak and preventing damage to those concerned. We will investigate the breach to determine how and what data was leaked, what the cause of the breach was and who had access to the leaked data. We will take actions to prevent this from happening again. When we find illegal acts have been a factor in the data breach we will report this to the police.

Who do we inform about a data breach

We will inform all persons and organisations affected by the data breach. We will inform the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) whenever Personally Identifiable Information is involved.