SECURITY
Report suspected vulnerabilities privately.
A useful report helps reproduce the issue without exposing customer data, production credentials, or a live store to unnecessary risk.
Email a security reportPrivate reporting channel
Email liyitao459@gmail.com with “CertaCart security report” in the subject. Do not open a public WordPress.org support topic for an unpatched vulnerability, and do not include passwords, license keys, payment-card data, customer records, or a production database.
What to include
State the affected CertaCart version, WordPress and WooCommerce versions, the security impact, the smallest reproducible sequence, and any prerequisite role or configuration. Include a safe proof of concept only when it does not access or alter data that you do not own.
Responsible handling
Please allow a reasonable period to reproduce, assess, fix, and distribute an update before public disclosure. You will receive an acknowledgement under the normal support response target. CertaCart does not currently advertise a paid bug-bounty programme.
Security boundaries
CertaCart stores its product fields, settings, scans, profiles, and operation history in the merchant’s WordPress database. WordPress administrators remain responsible for secure hosting, updates, least-privilege access, backups, and incident response for their own sites.
Last reviewed: September 4, 2026