Skip to content

Security & responsible disclosure

Responsible disclosure for Appestra and BlitzFunnel security reports.

Last updated: August 8, 2026

We take the security of Appestra products, the storefront, and customer data seriously. This page explains how to report vulnerabilities responsibly.

Reporting a vulnerability

Email support@appestra.com with the subject line Security report. Include a clear description, affected product and version (BlitzFunnel free / Pro / storefront), steps to reproduce, impact if known, and your contact details. Please do not disclose issues publicly until we have had a reasonable time to investigate and ship a fix.

Our response commitment

We aim to acknowledge valid reports within a few business days and will coordinate remediation when appropriate. We do not currently operate a paid bug bounty. Good-faith research that follows this policy will not be treated as abuse.

Scope

  • Appestra-owned websites and commerce platform
  • BlitzFunnel free (WordPress.org) and BlitzFunnel Pro
  • License and update APIs operated by Appestra

Out of scope

  • Third-party hosting misconfigurations on customer sites
  • Unrelated WordPress plugins or themes
  • Social engineering of Appestra staff or customers
  • Denial-of-service testing without prior written approval

General product support (non-security) can use the same address — mark security-sensitive reports clearly in the subject line. See also Privacy and Contact.