Ranking Suite Security Policy
We take Ranking Suite's security seriously. If you found a vulnerability, tell us privately: we will confirm it, fix it and give you credit.
Last updated: October 3, 2026
1. How to report a vulnerability
Use one of these private channels:
- E-mail: contato@ranking.bhz.br, with the subject "[Segurança] Ranking Suite";
- Patchstack vulnerability disclosure program: patchstack.com/database/vdp/ranking-suite — this channel will be available from the plugin's launch.
Do not disclose the vulnerability on the WordPress.org forum, on social media or anywhere public before a fix exists. This protects the sites that use the plugin.
2. What to include in your report
- the Ranking Suite, WordPress and PHP versions where the issue appears;
- the type of vulnerability and what an attacker could do with it (the impact);
- step-by-step instructions to reproduce it, preferably on a clean test site;
- a proof of concept, if you have one (code, request or video);
- whether you want to be credited in the acknowledgments, and with which name and link.
Only test on sites you own or on test environments, without accessing, changing or deleting other people's data.
3. Response times
- Acknowledgment of your report: within 3 business days;
- Fix for a critical vulnerability: within 14 days after the issue is confirmed;
- Less severe issues are fixed in one of the next releases. In every case, we keep you updated on the progress.
4. Coordinated disclosure
We ask you to keep the vulnerability confidential until the fix is released, or until a date we agree on together. Once the fixed version is out, the fix is announced in the plugin's changelog and you may publish the details. If we need more time than planned, we will explain why and agree on a new date with you.
5. Supported versions
We fix security issues only in the latest version of Ranking Suite. To stay protected, always keep the plugin up to date.
6. Acknowledgments
We publicly thank, on this page, everyone who responsibly reports a valid vulnerability (if they want to be credited).
7. Contact
Questions about this policy: contato@ranking.bhz.br. See also the Ranking Suite Terms of Use.