Reporting a vulnerability
Email [email protected] with the product or page, the steps, and what you observed. A person reads it. Please give us a reasonable window to fix before publishing; we do not run a bounty, and we do not threaten researchers.
The machine-readable version of this page is /.well-known/security.txt (RFC 9116). This is the human one.
Email [email protected] with the product or page, the steps, and what you observed. A person reads it. Please give us a reasonable window to fix before publishing; we do not run a bounty, and we do not threaten researchers.
No card numbers ever touch this server: payment is handled by Lemon Squeezy as merchant of record. We hold your order email, the licence keys we issued, and the download records — nothing more.
Administrator sign-in requires a second factor (TOTP). Payment webhooks are verified by signature before anything is fulfilled. The origin server sits behind Cloudflare and only accepts traffic from it. The database and buyer files are backed up nightly (04:17 UTC) and copied off the server every day.
Every live demo is an isolated container with sample data, reset regularly, published with a noindex header. Nothing you type into a demo reaches the store or another demo.
Full PHP source, so you can read what runs. Each product ships with two-factor sign-in for its own admin, signed webhooks, scoped API keys (read-only keys cannot write), backups, and an audit trail — and it never phones home.
Sign-in is by single-use magic link to the order email. Download links are time-limited and can be re-issued from the portal.
Could not load the questions — they are all on the FAQ page.
Email [email protected] with your order reference — include any error text and your PHP version if it is a setup issue.
No match — clear the filter or use Contact above.