Security and vulnerability disclosure
How to report a security problem to us, what we commit to in return, how long each product is supported, and what we publish when something goes wrong.
We would rather hear about a problem from you than from somebody's incident log. This page is the whole of our security posture in one place: how to reach us, what we do about it, how long we keep doing it, and what you can expect us to publish.
Reporting a vulnerability
Email: security@mashdiv.com
Please do not post it in an Envato item comment or a public issue. Those are read by people who cannot act on it, and are visible to people who should not learn about a vulnerability before there is a fix.
Send whatever you have — an incomplete report today beats a complete one in a fortnight. If you can, include the product and version, what an attacker can do in one sentence, how to reproduce it, and whether you have any reason to think it is already being exploited.
What we commit to
| When | What we do |
|---|---|
| Within 2 business days | Acknowledge your report and tell you who is handling it |
| Within 10 business days | Tell you whether we reproduced it, our severity assessment, and a target fix date |
| While we work | Update you at least every 10 business days, whether or not there is news |
| On release | Publish an advisory and credit you, unless you would rather we did not |
We ask for 90 days before public disclosure, or until a fix ships, whichever is sooner. If a vulnerability is already being exploited we will move faster than that and we will not ask you to hold on our account.
If we decide something is not a vulnerability we will tell you why rather than closing it quietly. Push back if you disagree.
Safe harbour
Research in good faith against your own installation will not attract legal action from us. Good faith means you do not touch other people's data, you do not degrade anyone's service, and you give us a reasonable chance to fix the problem before publishing.
This covers us only. Every deployment of this software belongs to an independent operator, and we cannot give you permission to test somebody else's system.
Security advisories
Published advisories are listed at Advisories.
They are also delivered straight into the admin panel of every registered installation running an affected version — you do not have to subscribe to anything or watch a page. An advisory tells you which versions are affected, which version fixes it, and what to do if you cannot upgrade today.
Advisories are published separately from release notes and can appear before a fix exists, describing a mitigation. That is deliberate: waiting for a release to tell you about a problem you could work around today would be the wrong way round.
Support periods
For each product we publish, the support period is the window in which we handle vulnerabilities and ship security updates for it.
- Security updates are free for the entire support period. You never need an active support subscription, an update licence, or anything else to receive one. This is separate from feature updates and from paid support.
- Security updates are provided separately from feature releases wherever that is technically possible, so you can take a fix without taking a redesign.
- The support period for each product, and its end date, is stated at the point of purchase and on your licence record.
A published table of every product's support period is being finalised and will appear here. Until then, ask us on the address above and we will tell you where a specific product stands.
What we do about our own supply chain
- We publish a software bill of materials for each product, listing the components it is built from, in CycloneDX format.
- Update archives are checksummed by the publisher and verified by your installation before extraction. An archive that does not match is discarded and nothing is written to your application directory.
- We monitor advisories for the components we depend on and pick up fixes that are reachable in our software.
Your responsibilities as an operator
We supply the software. You run it — which means you hold your users' data, you choose the configuration, and you decide when to patch. A few things only you can do:
- Apply security updates promptly. Most incidents we hear about involve an installation running a version whose fix shipped months earlier.
- Keep a working email on your Envato and store accounts, so a direct notification can reach you.
- Keep the installation registered, so advisories reach your admin panel.
- Read the advisory banner when one appears. Critical advisories cannot be dismissed, on purpose.
Regulatory position
We are the manufacturer of this software for the purposes of Regulation (EU) 2024/2847, the Cyber Resilience Act.
From 11 September 2026, where we become aware of an actively exploited vulnerability in our software, or of a severe incident affecting its security, we report it through ENISA's Single Reporting Platform within the deadlines the regulation sets — an early warning within 24 hours, a fuller notification within 72 hours, and a final report thereafter — and we inform affected users directly.
A vulnerability being disclosed to us, or being assigned a CVE, does not by itself make it reportable to the authorities; the trigger is evidence of active exploitation. That is a statement about what we file with a regulator, and it changes nothing about what we tell you: if there is a problem in software you are running, you hear about it either way.
From 11 December 2027 the remainder of the regulation applies, including technical documentation, conformity assessment and CE marking. Our Declaration of Conformity will be published here.