Last updated: 3 October 2026
Your licenses, downloads and data matter to us. This page explains how we protect them and how to report a vulnerability.
How we protect CraftRoq
- Encrypted everywhere — all traffic uses HTTPS with HSTS, and passes through Cloudflare’s network and firewall.
- License keys are never stored in plain text — we keep a keyed hash for lookups and an encrypted copy, so a database leak alone would not reveal working keys.
- Signed responses — every license and update response from portal.craftroq.com is digitally signed (Ed25519), and our plugins reject anything that is not.
- Private download links — plugin packages are only served through short-lived signed links to licensed sites.
- Passwordless customer sign-in — one-time links instead of passwords that could be reused or leaked.
- Locked-down admin — staff accounts need two-factor authentication or passkeys, use role-based permissions, and every sensitive action is written to an audit log.
- Abuse detection — rate limits, and alerts for unusual license activity such as key sharing.
Report a vulnerability
If you think you have found a security issue in a CraftRoq plugin, www.craftroq.com or portal.craftroq.com, please email [email protected] with the subject “Security”. Please include:
- What is affected (plugin and version, or URL).
- Steps to reproduce, and what an attacker could do.
- Any proof-of-concept code or screenshots.
We aim to acknowledge reports within 3 business days, keep you updated, and credit you when the fix is released if you would like.
Please
- Give us reasonable time to fix the issue before you disclose it publicly.
- Only test against your own sites and accounts — never other customers’ data or sites.
- Do not run denial-of-service, spam or social-engineering tests.
If you follow these guidelines in good faith, we will not take legal action against you for your research.
Keeping your site safe
- Keep WordPress, PHP and our plugins up to date — updates often include security fixes.
- Download CraftRoq Pro plugins only from your account, never from third-party sites.
- Never share your license key publicly; if it leaks, contact us and we will issue a new one.