Security & Vulnerability Disclosure Policy
At AF Themes, we take the security of our websites, WordPress themes, plugins, and services seriously. We appreciate the security community’s efforts to help us identify and responsibly address security vulnerabilities.
If you believe you have discovered a security vulnerability affecting an AF Themes product or service, we encourage you to report it to us so that we can investigate and address it appropriately.
Reporting a Vulnerability
Please report security vulnerabilities by email:
Email: afhelpteam@gmail.com
When reporting a vulnerability, please provide as much information as possible to help us understand and reproduce the issue.
A useful report should include:
- The affected AF Themes product or service.
- The affected version, if known.
- A clear description of the vulnerability.
- Steps required to reproduce the issue.
- The potential security impact.
- A proof of concept or demonstration, where appropriate.
- Any relevant screenshots, logs, requests, or other technical details.
- Suggested remediation, if you have one.
Please do not include passwords, private customer information, payment information, or other unnecessary sensitive information in your report.
What Happens After You Report
We will make a reasonable effort to:
- Acknowledge receipt of your report.
- Review and validate the reported vulnerability.
- Investigate the potential impact and affected products or versions.
- Work on an appropriate fix or mitigation when a vulnerability is confirmed.
- Communicate with the reporter when additional information is needed.
- Coordinate disclosure of the vulnerability where appropriate.
Response and remediation times may vary depending on the severity, complexity, affected products, and availability of a practical fix.
Responsible Disclosure
We ask security researchers to give us a reasonable opportunity to investigate and address a reported vulnerability before publicly disclosing technical details.
Please avoid:
- Publicly disclosing an unpatched vulnerability.
- Accessing, modifying, or deleting data that does not belong to you.
- Accessing customer accounts or websites without authorization.
- Disrupting the availability or performance of our services.
- Using automated testing at a volume that could affect our services.
- Performing social engineering, phishing, or physical attacks against AF Themes personnel or infrastructure.
- Testing vulnerabilities against other users’ websites or data.
If you accidentally encounter sensitive information while investigating a vulnerability, please stop testing and notify us immediately. Do not copy, modify, share, or retain the information unnecessarily.
Scope
We welcome reports concerning security vulnerabilities in AF Themes-controlled products and services, including where applicable:
- AF Themes websites and web applications.
- AF Themes WordPress themes.
- AF Themes WordPress plugins.
- AF Themes APIs and related services.
- Security vulnerabilities in AF Themes-developed code distributed through official channels.
For vulnerabilities in third-party software, hosting providers, payment processors, or other services that AF Themes does not control, please report the issue to the appropriate provider as well. We may also investigate issues involving third-party dependencies when they affect the security of an AF Themes product.
Out of Scope
The following generally do not qualify as security vulnerabilities unless they demonstrate a meaningful security impact:
- Spam or unsolicited communications.
- Social engineering or phishing attempts.
- Physical attacks.
- Denial-of-service or resource-exhaustion testing.
- Automated scanning that causes service degradation.
- Reports based solely on outdated software without demonstrating a security vulnerability.
- Missing security best practices without a demonstrated security impact.
- Self-XSS that cannot affect another user.
- Issues that require extensive user interaction without a realistic security impact.
- Vulnerabilities in third-party services that are unrelated to AF Themes code or infrastructure.
We may update the scope and out-of-scope categories as our products and services evolve.
Testing Guidelines
Security testing should be conducted responsibly and with minimal impact.
Researchers should:
- Test only against systems and products they are authorized to test.
- Use their own accounts and test environments whenever possible.
- Avoid accessing or modifying data belonging to other users.
- Avoid actions that could affect website availability or performance.
- Stop testing if they encounter sensitive user information.
- Provide enough technical information for us to reproduce the issue.
For vulnerabilities in publicly distributed WordPress themes and plugins, please use a controlled test environment whenever possible rather than testing against websites belonging to other users.
Coordinated Disclosure
For confirmed vulnerabilities, AF Themes may coordinate disclosure with the reporter and relevant security organizations or platforms when appropriate.
Depending on the nature and severity of a vulnerability, we may:
- Release a security update.
- Publish a security advisory.
- Credit the security researcher, with their permission.
- Coordinate a public disclosure date.
- Notify affected users where appropriate.
- Work with relevant WordPress security channels when applicable.
We will not publicly identify a researcher without permission.
Researcher Recognition
We appreciate responsible security researchers who help improve the security of AF Themes products.
With the researcher’s permission, we may acknowledge their contribution in a security advisory, changelog, or other appropriate communication.
Recognition is subject to the circumstances of the report and does not constitute an agreement to provide compensation unless explicitly agreed in advance.
Contact
For security vulnerabilities and security-related reports:
For general product support, please use the AF Themes Support page.
For privacy-related questions, please refer to our Privacy Policy.
Security.txt
Our security contact information is also published through the standard security.txt location:
The security.txt file provides security researchers and automated systems with our preferred security contact and vulnerability disclosure policy.
Updates to This Policy
We may update this policy as our products, services, security practices, and vulnerability disclosure processes evolve.
Last updated: August 2026
Themes.Plugins.Support
Focused on quality code and elegant design with incredible support. Kickstart your next project with AF themes, start building modern creative websites today!

