Skip navigation
Brasile.pro
IT / EN

Security

Report a vulnerability here.

This covers the plugins and the sites managed directly: a vulnerability found in either one gets an answer. Every report gets read, including the ones that turn out to be a false alarm.

Where to write

By email, in Italian or English. It is the same address as the Contact line of the security.txt file served by this site, as RFC 9116 requires.

security@brasile.pro

  • Subject: the product name and the word "security"
  • The message does not need to be encrypted, but a key can be agreed in two steps if you prefer

What the report needs

  • product and version, or the address of the site
  • what the flaw gets you, not only where it is
  • the steps to reproduce it, in order
  • test environment: WordPress version, PHP version, other active plugins
  • a link, if the issue is already public somewhere

What happens next

Times run from when the message arrives. If a date slips, you still get a message saying where the work stands.

  1. 72 hoursacknowledgement of the report, with the name of who handles it
  2. 5 working daysfirst assessment, severity, and whether the issue is confirmed
  3. 90 daysthe usual deadline for the fix and the public advisory. It gets shorter for an issue already being exploited, and the fix ships before the advisory
  4. on releasethe fix goes into a new version, with an entry in the changelog and credit to the reporter, if they want it

Out of scope

  • third party sites running the plugins, which go to their own owner
  • automated scanner output without proof that the flaw can be exploited
  • load and denial of service testing, which must not be attempted
  • social engineering aimed at people, clients or suppliers

No cash rewards

There is no bounty programme and no payment for reports. Anyone who reports a real issue is credited in the changelog and in the advisory, under the name they choose, or stays anonymous.

Obligations on the products sold

From 11 September 2026 the Cyber Resilience Act requires anyone selling software to run a reporting channel, a notification procedure towards ENISA for actively exploited vulnerabilities, and a bill of materials for each product. This page is that channel.

  • the bill of materials for a product can be requested at the same address
  • published advisories stay on the product page, with their date