Security and vulnerability disclosure
Have you found a security vulnerability in this website, in the shop or in one of my Joomla and WordPress plugins? Then please report it directly to me - not publicly. This page describes how to report, what you can expect from me and which rules apply.
Contact point for security reports
security@tonino-gerns.de. Reporting languages: German or English. Available in machine-readable form in /.well-known/security.txt in accordance with RFC 9116.
Helpful for fast processing: the affected product and version, a step-by-step description to reproduce the issue, the expected and the actual effect and - if available - proof-of-concept code or screenshots.
What you can expect from me
- Acknowledgment of receipt within 3 working days.
- Initial assessment (confirmed, not a bug, follow-up questions) within 10 working days.
- Remediation: critical and easily exploitable vulnerabilities as quickly as possible, with a target of 30 days from confirmation. For lower severity, the fix is scheduled for the next regular release.
- Publication: Once the update has been provided, the fixed vulnerability is described in the product's changelog - with its impact, the affected versions and the version that contains the fix.
- Coordinated disclosure: I ask you to refrain from publishing details for 90 days from your report. If a fix is available and delivered earlier, the period ends correspondingly earlier. On request, I will credit you in the changelog as the finder.
There is no bug bounty program, so no rewards are paid. Reports are nevertheless taken seriously and processed promptly.
Scope
- www.tonino-gerns.de including the shop and customer account
- all Joomla and WordPress extensions published by me, both paid and free
Out of scope: third-party services that are merely integrated (for example payment processing, reCAPTCHA or hosting infrastructure). Please report such findings directly to the respective provider - a note to me is still welcome.
Rules for security researchers
Anyone who follows the rules below need not fear legal action from me. I regard such reports as a welcome contribution to the security of my products.
- No denial-of-service tests, no load testing, no spam.
- No access to other people's accounts or data. If proof with your own test account is sufficient, use that account. If you unavoidably come into possession of other people's data: stop the access immediately, store nothing, pass nothing on, and mention it in your report.
- No social engineering, no physical access, no attacks on employees or customers.
- No permanent changes to data or systems and no backdoors.
- No publication before the period stated above has expired.
Security updates and support period
For each product, I provide security updates for at least 5 years from the placing on the market of the respective product version. Security updates are free of charge and are delivered separately from feature updates so that they can be installed without functional changes. If the support period of a product ends, this will be announced in advance on the respective product page.
Support period here means the provision of security updates within the meaning of the Regulation. Feature updates, adaptations to future major versions of Joomla or WordPress and individual support services are not included; these are governed by the purchased license.
You receive updates via the built-in update function of Joomla or WordPress and as a download in your customer account. The checksum of each package is stored in the update manifest, and a software bill of materials (SBOM) is included with every release.
Legal framework
This policy implements the requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847, Annex I Part II point 5 and Article 13). In addition, I report actively exploited vulnerabilities and severe security incidents to the competent European bodies within the applicable deadlines - early warning within 24 hours, notification within 72 hours, final report after remediation. I inform affected users as soon as an update or a countermeasure is available.