Skip to content

Security: aegiswp/theme

.github/SECURITY.md

Security Policy

Supported Versions

We actively support and provide security updates for the following branches:

Version Supported Security Updates
1.0.x
main

Reporting a Vulnerability

Please do not open a public GitHub issue for security vulnerabilities.

To report a security issue, please follow these steps:

  1. Email: Send your report to mail@atmostfear-entertainment.com
  2. PGP Key: Available at https://www.atmostfear-entertainment.com/aegis/security/pgp for encrypted communications
  3. Include:
    • Detailed description of the vulnerability
    • Proof of concept or steps to reproduce
    • Potential impact assessment
    • WordPress version and environment details

Response Timeline

  • Initial Response: Within 48 hours
  • Detailed Assessment: Within 5 business days
  • Patch Release: Within 14 days for critical vulnerabilities
  • Public Disclosure: After patch is available (typically 7-14 days later)

Security Best Practices

For users of the Aegis theme:

  1. Keep Updated: Always use the latest version
  2. WordPress Core: Maintain updated WordPress installation
  3. Plugins: Use reputable, updated plugins
  4. Permissions: Follow WordPress file permission guidelines
  5. Backups: Maintain regular, secure backups

Scope

This security policy covers:

  • Core theme files and functionality
  • Built-in blocks and components
  • Theme framework code
  • Official block patterns

Out of Scope

Third-party plugins, custom code, or modified theme files are not covered under this security policy.

Coordinated Disclosure

We follow responsible disclosure practices and work with researchers to ensure vulnerabilities are addressed before public disclosure.

For general bugs that are not security-related, please use our Bug Report Template.

There aren’t any published security advisories