Full details of the Automattic Security Policy can be found on automattic.com.
Generally, only the latest version of Jetpack has continued support. If a critical vulnerability is found in the current version of Jetpack, we may opt to backport any patches to previous versions.
Jetpack is an open-source plugin for WordPress. Our HackerOne program covers the plugin software, as well as a variety of related projects and infrastructure.
For responsible disclosure of security issues and to be eligible for our bug bounty program, please submit your report via the HackerOne portal.
Our most critical targets are:
For more targets, see the In Scope section on HackerOne.
Please note that the WordPress software is a separate entity from Automattic. Please report vulnerabilities for WordPress through the WordPress Foundation's HackerOne page.
We're committed to working with security researchers to resolve the vulnerabilities they discover. You can help us by following these guidelines:
We also expect you to comply with all applicable laws. You're responsible to pay any taxes associated with your bounties.