Please report suspected vulnerabilities privately through GitHub's private vulnerability reporting for this repository. If that facility is unavailable, contact the repository owner through a private channel before publishing technical details.
Do not open a public issue containing:
- EDD Software Licensing keys or HTTP Authorization headers;
- customer, order, activation, or site-identifying data;
- private or signed download URLs;
- licensed Easy Digital Downloads extension source or archives; or
- credentials, secrets, or production server configuration.
Include the affected plugin version, impact, reproduction steps using synthetic data, and any proposed mitigation. Remove secrets from logs and screenshots. Reports will be acknowledged and assessed before a coordinated disclosure date is agreed.
Security fixes are developed against the current release line. Before a public 1.0 release, the repository's compatibility checks and plugin readme.txt are the authoritative statement of supported WordPress, PHP, Easy Digital Downloads, and Software Licensing versions.