Skip to content

Security: renduples/agent-builder-wp-plugin

SECURITY.md

Security Policy

Agentic Tech LLC maintains Agent Builder. We take reports about the plugin's security seriously and handle them as described below.

Reporting a vulnerability

Please report privately. Do not open a public GitHub issue, forum post or pull request for a security problem.

Include the affected version, the steps to reproduce, and the impact you observed. A proof of concept helps. Please do not test against sites you do not own.

What we commit to

Step Target
Acknowledge your report Within 3 business days
Fix critical and high-severity issues Within 14 days of confirming them
Fix medium-severity issues Within 30 days of confirming them
Coordinated public disclosure After a fixed version is available, normally within 30 days of your report

We credit reporters in the changelog and advisory unless you ask us not to.

Scope

  • Agent Builder (WordPress.org edition, this repository)
  • Agent Builder self-hosted edition and Agent Builder Pro
  • Hosted services under *.agentic-plugin.com that the plugin connects to

Out of scope: vulnerabilities in WordPress core, other plugins or themes, and third-party AI providers. Please report those to their own maintainers. Social engineering, physical attacks and denial-of-service testing are also out of scope.

Supported versions

Security fixes are released for the latest version. Please update to the latest release before reporting.

Safe harbour

We will not pursue legal action against good-faith research that follows this policy: report privately, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosure.

There aren't any published security advisories