---
title: "Security reports · Ing. Massimiliano Brasile"
description: "How to report a vulnerability in the plugins signed by Massimiliano Brasile: address, what to write, response times."
url: https://brasile.pro/en/security/
lang: en
---
Security

# Report a vulnerability here.

This covers the plugins and the sites managed directly: a vulnerability found in either one gets an answer. Every report gets read, including the ones that turn out to be a false alarm.

## Where to write

By email, in Italian or English. It is the same address as the Contact line of the security.txt file served by this site, as RFC 9116 requires.

[security@brasile.pro](mailto:security@brasile.pro)

- Subject: the product name and the word "security"
- The message does not need to be encrypted, but a key can be agreed in two steps if you prefer

## What the report needs

- product and version, or the address of the site
- what the flaw gets you, not only where it is
- the steps to reproduce it, in order
- test environment: WordPress version, PHP version, other active plugins
- a link, if the issue is already public somewhere

## What happens next

Times run from when the message arrives. If a date slips, you still get a message saying where the work stands.

- **72 hours**acknowledgement of the report, with the name of who handles it
- **5 working days**first assessment, severity, and whether the issue is confirmed
- **90 days**the usual deadline for the fix and the public advisory. It gets shorter for an issue already being exploited, and the fix ships before the advisory
- **on release**the fix goes into a new version, with an entry in the changelog and credit to the reporter, if they want it

## Out of scope

- third party sites running the plugins, which go to their own owner
- automated scanner output without proof that the flaw can be exploited
- load and denial of service testing, which must not be attempted
- social engineering aimed at people, clients or suppliers

## No cash rewards

There is no bounty programme and no payment for reports. Anyone who reports a real issue is credited in the changelog and in the advisory, under the name they choose, or stays anonymous.

## Obligations on the products sold

From 11 September 2026 the Cyber Resilience Act requires anyone selling software to run a reporting channel, a notification procedure towards ENISA for actively exploited vulnerabilities, and a bill of materials for each product. This page is that channel.

- the bill of materials for a product can be requested at the same address
- published advisories stay on the product page, with their date

[security.txt](https://brasile.pro/.well-known/security.txt)

## Sources

- [Regulation (EU) 2024/2847, Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj)
- [RFC 9116, the security.txt file format](https://www.rfc-editor.org/rfc/rfc9116)
