# Report a Security Issue

> How to responsibly report security vulnerabilities in the WPsigner WordPress plugin.

edition: both
Edition: Lite + Pro
AI note: This page applies to Lite and Pro. Call out Lite limits (PDF only, max 2 signers, email OTP, local timestamp) when they apply. Do not invent Pro-only features.
HTML: https://docs.wpsigner.com/support/security/
Markdown: https://docs.wpsigner.com/md/support/security.md
Source file: support/security.md

---

If you believe you have found a security issue in WPsigner, please report it through our managed disclosure program. Do not post it publicly until we have had a chance to fix it.

WPsigner works with [Patchstack](https://patchstack.com/for-plugins/) to review reports, coordinate patches, and protect customers.

## Report a vulnerability

<iframe title="Report a security vulnerability in WPsigner" width="100%" height="700" style="max-width:500px;border:0;border-radius:12px;" src="https://patchstack.com/iframe/vendor?uuids=b983bd49-bd9c-4e59-9a6c-365e9be98cdc&theme=light" loading="lazy"></iframe>

[Open the reporting form in a new tab →](https://patchstack.com/database/vdp/wpsigner)

## What to include

- WPsigner version, plus WordPress and PHP versions
- Steps to reproduce the issue
- What an attacker could do if the issue were exploited
- Screenshots or a proof-of-concept, if you have one

## What happens next

1. Patchstack validates the report.
2. If it is confirmed, we receive the details and prepare a fix.
3. We release an update and coordinate disclosure when appropriate.

## Scope

This program covers the **WPsigner plugin** only. General product support is on the [support overview](/support/) page or [wpsigner.com/contact](https://wpsigner.com/contact/).

For the same policy on our main site, see [wpsigner.com/security](https://wpsigner.com/security/).
