WordPress controls
Settings and reviewed facts are sanitized, output is escaped, and administrative changes require appropriate capabilities and nonces.
Security · current production description
The plugin does not transmit shopper, cart or order contents. The Notice27 service separately processes the minimum purchaser and fulfilment data needed for checkout verification, licensing, delivery and account recovery. The description below explains the implemented boundaries; it is not a certification.
Data map
| Data | Where it stays | Notice27 service |
|---|---|---|
| Product decisions and settings | Your WordPress database | No |
| WooCommerce shopper, cart and order contents | Your WooCommerce database | The plugin does not transmit them |
| Purchaser contact and fulfilment metadata | Notice27 licence service | Checkout email, a one-way Stripe-session digest, and limited licence, entitlement and delivery records |
| Payment-card data | Stripe Checkout | Notice27 never receives full card data |
| Normalized site domain | WordPress and Notice27 licence service | For trial, activation and validation |
| Random site identifier | WordPress and Notice27 licence service | For bounded site activation |
| Plugin / WordPress / WooCommerce / PHP versions | WordPress and Notice27 licence service | For compatibility and update decisions |
| Licence key | Entered by the administrator | Sent only for activation; stored server-side as a one-way digest |
| Support diagnostics | WordPress until you deliberately submit them | Only after a merchant-initiated support action |
Settings and reviewed facts are sanitized, output is escaped, and administrative changes require appropriate capabilities and nonces.
Customer order records require order ownership, the WooCommerce order key or an authorised management capability. A guessed identifier reveals no order key or record.
Stripe Checkout handles payment data. Notice27 fulfils only after server-side retrieval confirms a complete, paid session with the expected product metadata. Duplicate callbacks are idempotent.
Downloads use short-lived grants. WordPress update metadata is signed and the plugin verifies the archive checksum before installation.
Responsible reporting
Email contact@kastovia.com with “Notice27 security” in the subject, the affected version or URL, impact and safe reproduction steps. Do not access other customers' data or publish an unremediated exploit.