Security
Last updated: 30 September 2026
Report a vulnerability
Email info@steuberdesign.nl with "Security" in the subject. Please don't report vulnerabilities in the public support forum. Include:
- the plugin (free or Pro) and the version you tested;
- what the vulnerability is and what an attacker could do with it;
- the steps to reproduce it, or a proof of concept;
- whether and how you would like to be credited.
Our contact details are also in /.well-known/security.txt.
Coordinated disclosure policy
- We confirm that we received your report within 3 business days.
- We investigate, keep you informed of our progress and work on a fix.
- We agree on a disclosure date with you. We publish the details once a fixed version is available, and at the latest 90 days after your report.
- We credit you in the changelog or the advisory, unless you would rather stay anonymous.
We ask you to:
- give us the chance to fix the issue before you share it with anyone else;
- only test on sites you own or are allowed to test;
- not access, change or delete other people's data, and not disrupt any service.
If you act in good faith and follow this policy, we will not take legal action against you for your research.
Scope
This policy covers Glutenberg Logic and Glutenberg Logic Pro. Vulnerabilities in the Freemius SDK that ships with the plugin are welcome too; we pass them on to Freemius. Issues in WordPress itself, or in other plugins and themes, should go to their own developers.
EU Cyber Resilience Act
Where the EU Cyber Resilience Act applies, we report actively exploited vulnerabilities and severe security incidents to the competent authorities as the Act requires, and we inform our users.
