Security & responsible disclosure
Responsible disclosure for Appestra and BlitzFunnel security reports.
Last updated: August 8, 2026
We take the security of Appestra products, the storefront, and customer data seriously. This page explains how to report vulnerabilities responsibly.
Reporting a vulnerability
Email support@appestra.com with the subject line Security report. Include a clear description, affected product and version (BlitzFunnel free / Pro / storefront), steps to reproduce, impact if known, and your contact details. Please do not disclose issues publicly until we have had a reasonable time to investigate and ship a fix.
Our response commitment
We aim to acknowledge valid reports within a few business days and will coordinate remediation when appropriate. We do not currently operate a paid bug bounty. Good-faith research that follows this policy will not be treated as abuse.
Scope
- Appestra-owned websites and commerce platform
- BlitzFunnel free (WordPress.org) and BlitzFunnel Pro
- License and update APIs operated by Appestra
Out of scope
- Third-party hosting misconfigurations on customer sites
- Unrelated WordPress plugins or themes
- Social engineering of Appestra staff or customers
- Denial-of-service testing without prior written approval
General product support (non-security) can use the same address — mark security-sensitive reports clearly in the subject line. See also Privacy and Contact.