Security

Security is the product. Here's how we protect the data you trust us with.

What data we handle

WP Triage collects only technical metadata from connected WordPress sites — plugin and theme names and versions, WordPress core version, and PHP version. We never collect your site's content, database, customer records, or credentials.

Encryption in transit

All traffic between your browser, our API, and connected WordPress sites is encrypted using TLS. Plain HTTP requests are redirected to HTTPS.

Token model

Access control

Your sites and data are scoped to your account. Ingest endpoints are rate limited, and snapshot submissions are restricted to the site that owns the token.

Payments

Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We do not store full payment card details on our servers.

Responsible disclosure

If you believe you've found a security vulnerability in WP Triage, please report it to [email protected]. We ask that you give us a reasonable opportunity to investigate and remediate before any public disclosure, and that you avoid accessing or modifying data that isn't yours. We appreciate and acknowledge good-faith research.

Contact

For any security question, reach us at [email protected].