Legal

Security and responsible disclosure information.

The controls that protect customer accounts and licenses, your own responsibilities, and how to report a security concern responsibly.

This security and responsible disclosure information explains how to report a concern, what details to include, and which account or plugin data should stay private.

Policy

All in One WP Settings uses account controls, private package delivery, protected license validation, and operational logging to help protect customer access. Customers are responsible for protecting their account credentials and using licenses only on the intended account and site footprint. Security concerns can be reported through the published support or contact path so they can be reviewed safely.

Downloads are delivered privately to entitled accounts, license validation is protected against tampering, and operational logging helps detect abuse and misuse. Access to the customer portal is tied to your account credentials.

You can help keep your account secure by using a strong, unique password, keeping your login details private, and running licenses only on the accounts and sites they were purchased for. Most account-security incidents start with shared or reused credentials.

If you believe you have found a security issue, report it responsibly through the published support or contact path with enough detail to reproduce it, and avoid testing against other customers' accounts. Reports are reviewed so genuine issues can be addressed safely.

Shared responsibility

What we protect, and what you can do

Account security works best when the platform controls and your own habits pull in the same direction.

On our side

Releases are delivered privately to entitled accounts, license validation is hardened against tampering, and operational logging helps detect misuse of accounts and downloads.

On your side

Use a strong, unique password, keep login details private, and run licenses only on the accounts and sites they were bought for. Most incidents start with reused credentials.

Reporting an issue

Report a suspected vulnerability through the published support or contact path with steps to reproduce, and avoid testing against other customers' accounts while you investigate.

FAQ

Security FAQ

Use the published support or contact path and include clear steps to reproduce the issue. Please do not probe or run tests against other customers' sites or accounts while you investigate.

Avoid sharing full passwords, complete license keys, database dumps, or other secrets. A short description with reproduction steps is enough for the team to review a concern safely.

Entitled releases are delivered only to your account, license checks are hardened against tampering, and portal access depends on your own credentials. A strong, unique password is the single biggest thing you can do to stay secure.

There is no paid bounty program, but genuine, responsibly reported security issues are reviewed and addressed. Clear reproduction steps help the team confirm and fix a report quickly.

Reports sent through the published support or contact path are acknowledged and reviewed. Please keep the details private until an issue has been resolved, to protect other customers.