Skip to main content
NEW Didit KYC Identity Verification is live, verify signers with government ID & biometrics for eIDAS Advanced signatures Learn more

Security

Found a security issue in WPsigner? We appreciate responsible disclosure.

WPsigner handles sensitive documents and signatures. We work with Patchstack to review reports, coordinate fixes, and protect our customers.

Report a vulnerability

Use the form below or open it in a new tab on Patchstack. Please do not post security issues publicly before we have had a chance to address them.

Reporting guidelines

Helpful reports usually include:

  • WPsigner version and WordPress / PHP versions
  • Clear steps to reproduce the issue
  • What an attacker could achieve
  • Screenshots or proof-of-concept if available

Please avoid automated scanning against customer sites, social engineering, or denial-of-service attacks.

What happens next

  1. Patchstack validates your report.
  2. If confirmed, we receive the details and work on a fix.
  3. We release an update and coordinate public disclosure when it is safe to do so.

For general support (not security bugs), use our contact page.

Scope

This program covers the WPsigner WordPress plugin (inSigner). Third-party hosting, WordPress core, and other plugins on a customer site are out of scope unless they are directly exploited through WPsigner.