Vulnerability Disclosure
Version of 29 September 2026
If you find a security weakness (a vulnerability) in ShieldWave or in our WordPress plugin, write to us. This policy says what it covers, how to report a vulnerability, what happens next and on what terms we consent to your research.
1. Who is responsible and what the policy covers
1.1 Who is responsible
ShieldWave and the plugin are run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.
1.2 Scope
This policy covers:
- the website shieldwave.io and the subdomains of it that we run;
- the ShieldWave API;
- the WordPress plugin "Ensomedia Security powered by shieldwave.io" (on WordPress.org: ensomedia-security), together with the services of our server that it connects to.
2. How to report a vulnerability
Write to support@shieldwave.io with "Security" in the subject line. You can write in English or in Polish.
In your report, please give:
- a description of the vulnerability and of its possible effects;
- where it is: the address, the API function, or the version of the plugin and of WordPress;
- the steps that let us reproduce the problem;
- evidence limited to what is needed, without data of other people;
- the date and time of your research and the IP address you used, so that we can tell it apart from attacks;
- how we can contact you, and whether you want to be named in our thanks.
You can also report a vulnerability through CERT Polska (section 7). We process the data in your report in order to handle it; the Privacy Policy gives the details.
3. What happens after you report
3.1 Answer and assessment
- We confirm that we received your report within 3 working days.
- We assess the report within 10 working days of receiving it. We tell you the result: whether we accept the vulnerability, its severity and when we plan to fix it.
- We tell you when the fix is ready. If you wish, you can check it before information about the vulnerability is published.
Working days are Monday to Friday, except public holidays in Poland.
3.2 Repair timetable
We rate the severity of a vulnerability with the current version of the Common Vulnerability Scoring System (CVSS), at present 4.0. The periods run from the day we confirm the vulnerability.
| Severity | CVSS score | Fixed within |
|---|---|---|
| Critical | 9.0-10.0 | 7 days |
| High | 7.0-8.9 | 30 days |
| Medium | 4.0-6.9 | 60 days |
| Low | 0.1-3.9 | 90 days |
For the plugin, a fix means the release of an update of the plugin. If a fix needs more time, for example because it depends on another supplier, we will explain the reason to you and give you a new date.
4. Coordinated disclosure
- Please do not disclose details of the vulnerability before the publication date agreed with us.
- The default publication date is 90 days after the day of your report or, if the repair period in section 3.2 ends later, the day after it ends. We can agree an earlier date when the fix is already available. A later date needs your agreement.
- If the vulnerability is being actively exploited, we may publish earlier the information users need to protect themselves. We will tell you first.
- After the fix we publish a description of the vulnerability. For the plugin we do this in the plugin's change log on WordPress.org and, where it is justified, we ask for a CVE identifier.
5. Consent to research carried out under this policy
5.1 What we consent to
We treat research carried out in good faith and in line with this policy as authorised: as the operator of the systems listed in section 1.2, we consent to it. In connection with such research:
- we will not file a motion to prosecute for offences that Polish law prosecutes only on the motion of the injured party (Articles 267 § 5 and 268a § 3 of the Polish Penal Code);
- we will not bring a civil claim against you.
If anyone else starts proceedings about research carried out under this policy, we will confirm in writing, at your request, that it was carried out with our consent. If you are not sure whether a planned action falls within this policy, ask us before you start.
5.2 Rules for research
- Use only your own accounts. The free plan (Free) is enough for research.
- Do not access, change or delete data of other people. If you come across such data, stop, copy no more than you need to describe the problem, tell us, and delete the data when the matter is closed.
- Do not disrupt the service or put an excessive load on it.
- When you run ShieldWave checks during your research, check only sites of your own.
- Research the plugin on your own WordPress installation.
- Use a vulnerability only as far as needed to demonstrate it.
- Report the vulnerability without undue delay and do not disclose it before the date in section 4.
5.3 Limits of the consent
Our consent and our commitments concern only us and the systems in section 1.2. They do not cover systems of anyone else, including those we use, for example Stripe's payment pages or the infrastructure of our hosting provider. They do not bind the public prosecutor or other authorities in cases of offences prosecuted by the state on its own initiative. Nor do they bind authorities of other countries. They do not release you from the law that applies to you.
6. What is outside this policy
The consent in section 5 does not cover:
- denial-of-service (DoS) attacks and other actions that disrupt the service;
- social engineering, including phishing, against us, our customers or users;
- access to data or accounts of other customers;
- actions that need physical access to devices;
- checks of our customers' sites, including sites where the plugin runs, or pointing ShieldWave checks at sites that are not yours;
- research on systems of other companies we use; report their vulnerabilities to those companies directly.
7. CERT Polska
CERT Polska (CSIRT NASK) is the coordinator for coordinated vulnerability disclosure in Poland (Article 26a of the Polish Act of 5 July 2018 on the national cybersecurity system). You can report a vulnerability through the CERT Polska form: https://incydent.cert.pl. The form lets you stay anonymous. Use this route above all when we do not answer within the periods in section 3, or when we disagree about the assessment of the vulnerability or the publication date. We cooperate with CERT Polska as the coordinator.
8. Thanks
We do not pay rewards. If you wish, we will thank you publicly in the description of the fix, by your name or by a nickname.
9. The plugin and the Cyber Resilience Act
9.1 Manufacturer
The manufacturer of the plugin "Ensomedia Security powered by shieldwave.io" within the meaning of Regulation (EU) 2024/2847 (the Cyber Resilience Act) is ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland. The single point of contact for the plugin's security is support@shieldwave.io.
9.2 Security updates
- Security updates are free of charge.
- We publish them in the WordPress.org plugin directory, from where they reach your WordPress dashboard.
- Each security update comes with a description of what it fixes and of what you should do.
- We release fixes in the latest version of the plugin, so keep it up to date.
9.3 Support period
We release security updates for at least 5 years from the release of version 1.0.0 (September 2026), that is at least until September 2031.
9.4 Reporting actively exploited vulnerabilities and severe incidents
We report actively exploited vulnerabilities of the plugin and severe incidents affecting its security through the single reporting platform run by the European Union Agency for Cybersecurity (ENISA) to CSIRT NASK as the coordinator. We do so within the periods of Article 14 of the Cyber Resilience Act: an early warning within 24 hours, a notification within 72 hours, then a final report. We also inform the users of the plugin about the vulnerability or incident and about what they can do to limit its effects.
10. Change history
- 29 September 2026: new version. It replaces the vulnerability disclosure policy of February 2026, which described "ShieldWave Pro". The new version covers the WordPress plugin, gives a single contact address, names CERT Polska as the coordinator and describes the duties of the plugin's manufacturer.