Home › Security

Security & Vulnerability Disclosure

We take the security of WooCommerce store owners and their customers seriously. As an independent studio writing code that runs on your server, transparency and fast response times are our primary defense.

How we review security

Tillpress has not commissioned an independent third-party security audit yet. Security review is done in-house before each release. Admin actions check a nonce and user capability, inbound Twilio webhooks are rejected unless Twilio’s request signature verifies, database queries are parameterized, and Pro license responses are signature-checked. If you find a gap, we want to hear about it.

Reporting a Vulnerability

If you discover a security vulnerability in any Tillpress plugin (StoreCanvas, OrderRing, OrderBay, Checkout Sentinel) or our licensing infrastructure, please report it directly to us:

Primary Security Contact:

info@tillpress.com

Our Commitments

  • Initial Response: We acknowledge receipt of vulnerability reports within 24 hours.
  • Triage & Fix: Critical issues affecting store data integrity or unauthorized execution are prioritized for hotfix release within 7 business days.
  • Coordinated Disclosure: We observe standard 90-day responsible disclosure practices and request researchers coordinate public disclosures after a patch is available.
  • No Legal Action: We commit to not pursuing legal action against researchers acting in good faith according to these guidelines.

Patchstack Community & mVDP

Tillpress plugins participate in the WordPress security ecosystem. We monitor community vulnerability databases and welcome responsible disclosures through Patchstack mVDP (Managed Vulnerability Disclosure Program).

Machine-Readable Policy

Our machine-readable security policy is published in accordance with RFC 9116 at /.well-known/security.txt.