Back to CertaCart

SECURITY

Report suspected vulnerabilities privately.

A useful report helps reproduce the issue without exposing customer data, production credentials, or a live store to unnecessary risk.

Email a security report

Private reporting channel

Email liyitao459@gmail.com with “CertaCart security report” in the subject. Do not open a public WordPress.org support topic for an unpatched vulnerability, and do not include passwords, license keys, payment-card data, customer records, or a production database.

What to include

State the affected CertaCart version, WordPress and WooCommerce versions, the security impact, the smallest reproducible sequence, and any prerequisite role or configuration. Include a safe proof of concept only when it does not access or alter data that you do not own.

Responsible handling

Please allow a reasonable period to reproduce, assess, fix, and distribute an update before public disclosure. You will receive an acknowledgement under the normal support response target. CertaCart does not currently advertise a paid bug-bounty programme.

Security boundaries

CertaCart stores its product fields, settings, scans, profiles, and operation history in the merchant’s WordPress database. WordPress administrators remain responsible for secure hosting, updates, least-privilege access, backups, and incident response for their own sites.

Last reviewed: September 4, 2026

Install Free on WordPress.org