Security

Report a vulnerability

Last updated: October 3, 2026

Found a security problem in Sitekiln, or in the WordPress theme or plugin that Sitekiln exports? Please tell us. This page explains how to report it, what you can expect from us and what we ask of you. We work by coordinated vulnerability disclosure: you report to us first, we fix the problem, and details are published afterwards.

How to report

Send your report by e-mail to the address below. Write in Dutch or English.

Report to
azomo.tom@proton.me

There is no encryption key to use yet, so send only what is needed to reproduce the problem, and keep the details to yourself until it is fixed.

What to include

The more precise, the faster we can act:

  • What you found and where (a page, an API route, the theme or the plugin).
  • The steps to reproduce it, or a short proof of concept that does no harm.
  • What an attacker could do with it, in your own words.
  • The version or date you looked at (for the theme and the plugin: the Version line in style.css or in the plugin's main file).
  • How we can reach you, and whether we may name you as the finder once it is fixed.

What to expect

  • We acknowledge your report within 5 working days.
  • We assess it, tell you what we found and, when it is a real problem, roughly when it will be fixed. We keep you informed until it is closed.
  • Please give us a reasonable time to fix the problem before you publish anything; we will agree on a date with you.
  • Sitekiln has no reward programme: we cannot pay for reports.

Good-faith research

If you act in good faith and stay within this policy, we will not take legal action against you, and we will not ask the authorities to prosecute you, for finding and reporting a vulnerability within the scope below. This promise does not cover anything done with bad intent, anything outside the scope, or harm to other people's data. It comes from us; it does not bind third parties such as the model providers or a customer's own host.

Scope

In scope:

  • Sitekiln: the web application at this address, including its API.
  • The WordPress theme and the Sitekiln Core plugin that Sitekiln exports for its customers.

Not in scope:

  • The websites that customers build and host: report a problem in a customer's own website to that customer.
  • Services Sitekiln uses, such as the model providers, stock-photo services and WordPress itself: report those to their own owners.
  • Denial-of-service attacks, spam, social engineering, physical attacks and automated scanning at a rate that disturbs the service.

Please do not

While you test, please do not:

  • access, change or keep other people's data: stop as soon as you see personal data, and tell us
  • disrupt the service or other users
  • go further than needed to show that the problem exists
  • make your report depend on a payment

security.txt

The same contact is published as a security.txt file (RFC 9116) at /.well-known/security.txt.

Back to Sitekiln