How to report
Email security@defaultgone.com.au with a clear, reproducible description of the issue. PGP not required — the inbox is monitored. We treat the contents of the report as confidential.
The canonical machine-readable contact lives at /.well-known/security.txt per RFC 9116.
What we’ll do
- Acknowledge your report within 5 business days.
- Triage and confirm reproducibility, then keep you posted on remediation.
- Credit you publicly (if you wish) once a fix has shipped.
- Not pursue legal action against good-faith researchers who follow this policy.
In scope
defaultgone.com.auand its subdomains we directly operate.- The Default Gone WordPress plugin and child theme on this host.
- Public-facing REST endpoints under
/wp-json/dg/v1/*.
Out of scope
- Third-party services we use (Stripe, Resend, SiteGround, Trustpilot, etc.) — please report directly to those providers.
- Findings on test or staging hosts we don’t own.
- Reports from automated scanners with no demonstrated impact.
- Denial-of-service techniques, social engineering of staff or consumers, or anything that requires intercepting third-party traffic.
- Best-practice issues without a concrete attack scenario (missing CSP directive variants, header strictness preferences, etc.).
Safe-harbour expectations
We ask that researchers:
- Don’t access, modify, or delete data that isn’t your own.
- Don’t run intrusive automated scans against production beyond what is needed to demonstrate the issue.
- Don’t publicly disclose the issue until we’ve had a reasonable chance to ship a fix — typically 90 days, sooner if the fix is straightforward.
Bounty
Default Gone does not currently run a paid bug-bounty programme. We’ll credit valid reports publicly (with your permission) and we’re happy to send a small thank-you for high-impact findings.