Security

How we protect CraftRoq, and how to report a vulnerability.

Last updated: 3 October 2026

Your licenses, downloads and data matter to us. This page explains how we protect them and how to report a vulnerability.

How we protect CraftRoq

  • Encrypted everywhere — all traffic uses HTTPS with HSTS, and passes through Cloudflare’s network and firewall.
  • License keys are never stored in plain text — we keep a keyed hash for lookups and an encrypted copy, so a database leak alone would not reveal working keys.
  • Signed responses — every license and update response from portal.craftroq.com is digitally signed (Ed25519), and our plugins reject anything that is not.
  • Private download links — plugin packages are only served through short-lived signed links to licensed sites.
  • Passwordless customer sign-in — one-time links instead of passwords that could be reused or leaked.
  • Locked-down admin — staff accounts need two-factor authentication or passkeys, use role-based permissions, and every sensitive action is written to an audit log.
  • Abuse detection — rate limits, and alerts for unusual license activity such as key sharing.

Report a vulnerability

If you think you have found a security issue in a CraftRoq plugin, www.craftroq.com or portal.craftroq.com, please email [email protected] with the subject “Security”. Please include:

  • What is affected (plugin and version, or URL).
  • Steps to reproduce, and what an attacker could do.
  • Any proof-of-concept code or screenshots.

We aim to acknowledge reports within 3 business days, keep you updated, and credit you when the fix is released if you would like.

Please

  • Give us reasonable time to fix the issue before you disclose it publicly.
  • Only test against your own sites and accounts — never other customers’ data or sites.
  • Do not run denial-of-service, spam or social-engineering tests.

If you follow these guidelines in good faith, we will not take legal action against you for your research.

Keeping your site safe

  • Keep WordPress, PHP and our plugins up to date — updates often include security fixes.
  • Download CraftRoq Pro plugins only from your account, never from third-party sites.
  • Never share your license key publicly; if it leaks, contact us and we will issue a new one.