Skip to content

Security: pluginslab/wp-agentic-admin

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in WP Agentic Admin, please report it responsibly.

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, please email: security@pluginslab.com

You should receive a response within 48 hours. We will work with you to understand the issue and coordinate a fix before any public disclosure.

Scope

This policy covers the WP Agentic Admin WordPress plugin, including:

  • PHP backend code (REST API endpoints, abilities, settings)
  • JavaScript frontend code (React components, service worker, chat interface)
  • The Abilities API and third-party integration surface

Out of Scope

  • The WebLLM library and its dependencies (report upstream)
  • The Qwen models themselves (report to the model authors)
  • WordPress core vulnerabilities (report to WordPress security team)

Supported Versions

Version Supported
Latest release Yes
Older releases No

We recommend always running the latest version.

There aren’t any published security advisories