We aim to support the latest published version of Spectre UI WordPress. Security updates are applied to the current major version only.
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
| < 0.1 | ❌ |
Please ensure you are using the most recent version of both:
- The Spectre UI WordPress plugin
@phcdevworks/spectre-ui(updated inpackage.json)
Older releases may not receive security fixes.
If you discover a security vulnerability, please DO NOT open a public issue. Security issues should be reported privately to protect users.
Preferred method: Use GitHub Security Advisories to privately report vulnerabilities
Alternative methods:
- Email the maintainers at [security contact - see repository]
- Direct message maintainers through GitHub
Please provide as much detail as possible to help us reproduce and assess impact:
- Description of the vulnerability and potential impact
- Steps to reproduce or proof-of-concept code
- Affected versions (if known)
- Potential attack scenarios
- Suggested mitigation (if you have ideas)
- Acknowledgment: We will acknowledge receipt within 48 hours
- Assessment: We will investigate and provide an initial assessment within 5 business days
- Updates: We will keep you informed of the fix status throughout the process
- Resolution: We will work on a fix and coordinate disclosure timing with you
- Credit: We will credit you in the security advisory (unless you prefer to remain anonymous)
We appreciate responsible disclosure and will work with you to:
- Understand the scope and severity of the issue
- Develop and test a fix
- Coordinate public disclosure timing
- Credit your contribution (if desired)
Please allow us reasonable time to address the issue before public disclosure.
When using Spectre UI WordPress:
- Keep WordPress updated to the latest version
- Update the plugin regularly via
npm installand rebuild - Monitor dependencies for known vulnerabilities (
npm audit) - Use HTTPS for all WordPress sites
- Follow WordPress security best practices for themes and plugins
This security policy covers:
- The Spectre UI WordPress plugin code
- CSS synchronization scripts
- Build pipeline security
- WordPress-specific integrations
This policy does NOT cover:
- Vulnerabilities in WordPress core (report to WordPress.org)
- Vulnerabilities in third-party themes or plugins
- Issues in
@phcdevworks/spectre-ui(report to that repository) - Issues in
@phcdevworks/spectre-tokens(report to that repository)
For security-related questions that aren't vulnerabilities:
- Open a GitHub Discussion
- Tag maintainers in relevant issues
Thank you for helping keep Spectre UI WordPress and our community safe!