Vulnerability Disclosure

Version of 29 September 2026

If you find a security weakness (a vulnerability) in ShieldWave or in our WordPress plugin, write to us. This policy says what it covers, how to report a vulnerability, what happens next and on what terms we consent to your research.

1. Who is responsible and what the policy covers

1.1 Who is responsible

ShieldWave and the plugin are run by Radosław Fedorczuk, trading as ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland, tax number (NIP) 8952195742, EU VAT number PL8952195742, business register number (REGON) 381626230, entered in the Polish Central Register and Information on Economic Activity (CEIDG), "ENSOMEDIA" or "we" below.

1.2 Scope

This policy covers:

2. How to report a vulnerability

Write to support@shieldwave.io with "Security" in the subject line. You can write in English or in Polish.

In your report, please give:

You can also report a vulnerability through CERT Polska (section 7). We process the data in your report in order to handle it; the Privacy Policy gives the details.

3. What happens after you report

3.1 Answer and assessment

Working days are Monday to Friday, except public holidays in Poland.

3.2 Repair timetable

We rate the severity of a vulnerability with the current version of the Common Vulnerability Scoring System (CVSS), at present 4.0. The periods run from the day we confirm the vulnerability.

SeverityCVSS scoreFixed within
Critical9.0-10.07 days
High7.0-8.930 days
Medium4.0-6.960 days
Low0.1-3.990 days

For the plugin, a fix means the release of an update of the plugin. If a fix needs more time, for example because it depends on another supplier, we will explain the reason to you and give you a new date.

4. Coordinated disclosure

We treat research carried out in good faith and in line with this policy as authorised: as the operator of the systems listed in section 1.2, we consent to it. In connection with such research:

If anyone else starts proceedings about research carried out under this policy, we will confirm in writing, at your request, that it was carried out with our consent. If you are not sure whether a planned action falls within this policy, ask us before you start.

5.2 Rules for research

Our consent and our commitments concern only us and the systems in section 1.2. They do not cover systems of anyone else, including those we use, for example Stripe's payment pages or the infrastructure of our hosting provider. They do not bind the public prosecutor or other authorities in cases of offences prosecuted by the state on its own initiative. Nor do they bind authorities of other countries. They do not release you from the law that applies to you.

6. What is outside this policy

The consent in section 5 does not cover:

7. CERT Polska

CERT Polska (CSIRT NASK) is the coordinator for coordinated vulnerability disclosure in Poland (Article 26a of the Polish Act of 5 July 2018 on the national cybersecurity system). You can report a vulnerability through the CERT Polska form: https://incydent.cert.pl. The form lets you stay anonymous. Use this route above all when we do not answer within the periods in section 3, or when we disagree about the assessment of the vulnerability or the publication date. We cooperate with CERT Polska as the coordinator.

8. Thanks

We do not pay rewards. If you wish, we will thank you publicly in the description of the fix, by your name or by a nickname.

9. The plugin and the Cyber Resilience Act

9.1 Manufacturer

The manufacturer of the plugin "Ensomedia Security powered by shieldwave.io" within the meaning of Regulation (EU) 2024/2847 (the Cyber Resilience Act) is ENSOMEDIA Radosław Fedorczuk, ul. Chorwacka 33/42, 51-107 Wrocław, Poland. The single point of contact for the plugin's security is support@shieldwave.io.

9.2 Security updates

9.3 Support period

We release security updates for at least 5 years from the release of version 1.0.0 (September 2026), that is at least until September 2031.

9.4 Reporting actively exploited vulnerabilities and severe incidents

We report actively exploited vulnerabilities of the plugin and severe incidents affecting its security through the single reporting platform run by the European Union Agency for Cybersecurity (ENISA) to CSIRT NASK as the coordinator. We do so within the periods of Article 14 of the Cyber Resilience Act: an early warning within 24 hours, a notification within 72 hours, then a final report. We also inform the users of the plugin about the vulnerability or incident and about what they can do to limit its effects.

10. Change history