Security and responsible reporting
The plugin stays local; payment and download access stay separated.
Notice27 is designed to minimize data and dependencies. This page describes the current implementation, not a certification or penetration-test claim.
Draft security and responsible-disclosure policy for professional review.
Last updated: 27 July 2026
Plugin boundary
Version 1.2 contains no outbound HTTP request, telemetry, advertising, licence server, remote asset, customer-data read, or custom authentication. It stores one settings option in the merchant's WordPress database.
Settings are sanitized; output is escaped; the reset action requires the WooCommerce management capability and a valid WordPress nonce.
Website, payment, and delivery
Stripe Checkout handles card data. The Notice27 server uses the configured secret only to create/retrieve Checkout Sessions and checks complete, paid, matching product metadata before serving the protected ZIP.
Never email a Stripe key, WordPress password, card number, customer export, database, or production backup.
Report a vulnerability
Email contact@kastovia.com with “Notice27 security” in the subject, affected version/URL, impact, and safe reproduction steps. Do not access other customers' data, disrupt service, or publish an unremediated exploit.
Kastovia has not yet approved a response-time or bounty promise. Receipt and remediation will be handled according to severity and available evidence.