Agentic Tech LLC maintains Agent Builder. We take reports about the plugin's security seriously and handle them as described below.
Please report privately. Do not open a public GitHub issue, forum post or pull request for a security problem.
- Patchstack (preferred): Agent Builder Vulnerability Disclosure Program. Patchstack helps with verification and CVE assignment and notifies us.
- Email: security@agentic-plugin.com
- GitHub: use "Report a vulnerability" on this repository's Security tab (private advisory).
Include the affected version, the steps to reproduce, and the impact you observed. A proof of concept helps. Please do not test against sites you do not own.
| Step | Target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Fix critical and high-severity issues | Within 14 days of confirming them |
| Fix medium-severity issues | Within 30 days of confirming them |
| Coordinated public disclosure | After a fixed version is available, normally within 30 days of your report |
We credit reporters in the changelog and advisory unless you ask us not to.
- Agent Builder (WordPress.org edition, this repository)
- Agent Builder self-hosted edition and Agent Builder Pro
- Hosted services under
*.agentic-plugin.comthat the plugin connects to
Out of scope: vulnerabilities in WordPress core, other plugins or themes, and third-party AI providers. Please report those to their own maintainers. Social engineering, physical attacks and denial-of-service testing are also out of scope.
Security fixes are released for the latest version. Please update to the latest release before reporting.
We will not pursue legal action against good-faith research that follows this policy: report privately, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosure.