Security is the product. Here's how we protect the data you trust us with.
WP Triage collects only technical metadata from connected WordPress sites — plugin and theme names and versions, WordPress core version, and PHP version. We never collect your site's content, database, customer records, or credentials.
All traffic between your browser, our API, and connected WordPress sites is encrypted using TLS. Plain HTTP requests are redirected to HTTPS.
wpa_…) authorise a WordPress plugin to register sites against your account. They are stored as one-way hashes and shown to you only once.wpt_…) are issued per site and scope a site to submitting only its own snapshots.Your sites and data are scoped to your account. Ingest endpoints are rate limited, and snapshot submissions are restricted to the site that owns the token.
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We do not store full payment card details on our servers.
If you believe you've found a security vulnerability in WP Triage, please report it to [email protected]. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that you avoid accessing or modifying data that isn't yours. We appreciate and acknowledge good-faith research.
For any security question, reach us at [email protected].