Security

Found a vulnerability? Tell us.

We build security software, so we hold our own code to the same standard. If you have found a weakness in the Segurium plugin or in our services, we want to hear about it directly.

How to report

Email security@segurium.com. A human reads it.

A report is easiest to act on when it includes:

  • What the issue lets an attacker do, in one or two sentences.
  • The plugin or service version you tested.
  • Steps to reproduce it, with the requests or files involved.
  • How you would like to be credited, if you want to be.

Write in English if you can.

What we do with it

We confirm receipt of every report and tell you what we found when we have reproduced it, or why we disagree when we have not. We will let you know when a fix ships.

We do not commit to a fixed response time. We would rather answer honestly than publish a deadline we cannot always hold. In practice we reply quickly.

We ask that you keep the details private until a fix is available to our users. If you plan to publish, tell us your intended date and we will work to it or explain why we need longer.

Testing ground rules

Test against a WordPress install you own, or a disposable local lab. Do not test against other people's sites, and do not test against our production services.

Out of scope, and not worth your time:

  • Denial of service, traffic floods, and resource exhaustion.
  • Social engineering of our team, our users, or our suppliers.
  • Physical attacks, and attacks on third-party services we use.
  • Automated scanner output with no demonstrated impact — missing headers, version banners, and similar.

If you follow these rules and report to us in good faith, we will not pursue legal action over your research, and we will say so to anyone who asks.

Rewards

Segurium does not run a paid bug bounty program, and we have no reward budget for security findings.

What we do offer is public credit, on this page, for any report we accept and fix — see below.

Acknowledgements

These people found something in Segurium and told us privately first. We list them once the reported issue is fixed and the reporter has told us how they want to be named. Entries describe the class of issue only — we do not publish reproduction detail for issues in released versions.

  1. Shriyash Beohar and Artus Krohn-Grimberghe

    August 2026

    Joint research on the plugin's login-security handling, reported privately and in full.

Not a security issue?

For bug reports, missed detections, and everything else, use the contact form — it reaches the same team and gets triaged faster than a security mailbox.