Reporting a vulnerability
MxChat welcomes reports from security researchers. If you believe you have found a security vulnerability in the MxChat website or any MxChat WordPress plugin (the free core plugin or any Pro add-on), please email [email protected] with:
- A description of the issue and the plugin or site area affected (including the plugin version, if applicable)
- Steps to reproduce, or a proof of concept
- Your assessment of the impact
We will acknowledge your report within 3 business days and keep you informed as we investigate and fix the issue.
Scope
In scope: the mxchat.ai website, the MxChat core plugin distributed on WordPress.org, and all MxChat Pro add-ons distributed from mxchat.ai.
Out of scope: third-party services MxChat integrates with (OpenAI, Anthropic, Pinecone, and similar), denial-of-service testing, and social engineering.
Safe harbor
We will not pursue legal action against researchers who act in good faith: make a reasonable effort to avoid accessing other users’ data, do not degrade the service for others, and give us reasonable time to remediate before any public disclosure. Accidental access to data that is not yours should be reported and not retained.
Machine-readable contact
Our security contact is also published at /.well-known/security.txt per RFC 9116.