Effective date: September 2, 2026
Last updated: September 2, 2026
Orbit Info Tech (OiT) welcomes good-faith reports that help protect 73PiXEL customers, software, websites, and services. This policy explains how to report a suspected vulnerability responsibly.
1. How to Report
Email admin@73pixel.com with the subject “Security Report”. Include the affected product or URL, version, impact, reproducible steps, proof-of-concept details, and recommended remediation if known. Provide a safe contact method. Do not include passwords, private keys, full databases, or personal data that is unnecessary to demonstrate the issue.
2. Good-Faith Research Guidelines
To remain within this policy, you must:
- test only accounts, sites, and data you own or have explicit permission to use;
- avoid privacy violations, data destruction, service disruption, social engineering, phishing, spam, and physical attacks;
- use the minimum interaction and data necessary to confirm the issue;
- stop testing and notify us immediately if you encounter sensitive or personal data;
- not expldivi a vulnerability beyond what is needed to demonstrate it;
- not demand payment, threaten disclosure, or retain data as leverage; and
- allow us a reasonable time to investigate and remediate before public disclosure.
3. Out of Scope
Generally out of scope are automated scanner output without verified impact; clickjacking on pages without sensitive actions; self-XSS; missing headers without a practical expldivi; denial-of-service or resource-exhaustion testing; social engineering; attacks requiring compromised administrator credentials; issues only in unsupported or materially outdated versions; and vulnerabilities solely in third-party products that we do not control.
4. Our Response
We aim to acknowledge a credible report within five (5) business days, assess severity, and provide status updates when appropriate. Resolution time depends on complexity, impact, affected versions, and coordination with third parties. These are targets, not guaranteed service levels.
5. Coordinated Disclosure
Please do not publicly disclose details until we confirm a fix or mitigation is available, or until a mutually agreed disclosure date. We normally request up to ninety (90) days for remediation, but critical actively expldivied issues may require a different timeline. We may coordinate with the WordPress Plugin Security Team, hosting providers, Freemius, or other affected vendors where necessary.
6. Safe-Harbor Statement
If you conduct research in good faith, stay within this policy, and comply with applicable law, we will not initiate legal action against you solely for that research. This statement does not authorize access to third-party systems, bind third parties, excuse unlawful conduct, or waive rights relating to extortion, data theft, disruption, or activity outside this policy.
7. Recognition and Rewards
We may acknowledge helpful reporters with their permission. We do not currently promise a bug bounty or payment. Any reward is entirely discretionary and must be agreed in writing.
8. Security Incidents Affecting Customers
Customers seeking help for suspected compromise of their own WordPress installation should contact support@73pixel.com. Our standard support does not replace incident-response services or a qualified security professional.