Skip to content

Security: srmdn/foliocms

Security

SECURITY.md

Security Policy

Reporting

Report vulnerabilities privately. Do not open public issues for active vulnerabilities.

  • Primary contact: mail@saidwp.com
  • Alternate: private GitHub security advisory

Include:

  • affected versions/commits
  • reproduction steps or PoC
  • impact assessment
  • suggested mitigation

Response Targets

  • acknowledge within 72 hours
  • initial triage within 7 days
  • remediation/disclosure plan after validation

Coordinated Disclosure

Please wait for a fix or agreed mitigation window before public disclosure.

Portable vs Project-Specific

Portable:

  • private reporting requirement
  • response-time targets
  • coordinated disclosure flow

Project-specific:

  • security mailbox
  • severity taxonomy
  • SLA exceptions

There aren’t any published security advisories