Security & Responsible Disclosure
AdnanThemes takes website, product and customer-account security seriously. This page provides a clear route for reporting potential security issues responsibly.
Verified website safeguards
The live AdnanThemes website currently uses HTTPS and runs with WordPress production debugging disabled. Backup tooling is also installed as part of the website operations stack.
Encrypted website connection
AdnanThemes.com is served over HTTPS so browser traffic to the website is encrypted in transit.
Production configuration
WordPress debug mode is disabled on the live production website to avoid exposing development information to visitors.
Backup capability
Backup and restore tooling is installed in the WordPress environment to support operational recovery procedures.
How to report a potential vulnerability
If you believe you have found a security issue affecting AdnanThemes.com or an AdnanThemes product, please report it privately through the official contact route.
1. Provide enough detail
Include the affected URL or product, the issue type, steps to reproduce, and the potential impact. Screenshots or non-sensitive proof-of-concept details can help.
2. Protect customer data
Do not access, download, modify or expose data that is not yours. Do not publish secrets, customer information, credentials or private API keys.
3. Avoid disruption
Do not perform denial-of-service testing, destructive actions, spam, social engineering, physical attacks or activity that could interrupt service for other users.
Good-faith reporting
We appreciate responsible reports that are made to improve security and minimize harm. Please allow reasonable time for investigation and remediation before making a vulnerability public.
Scope
Reports may cover AdnanThemes.com, its customer-facing WordPress functionality, and AdnanThemes-owned software where the issue can be clearly demonstrated.
Third-party services
Issues that only affect third-party platforms, payment processors, marketplaces, hosting providers or external APIs should normally be reported to the relevant provider.
Sensitive information
Never send full payment-card information, account passwords or unrelated private customer data when reporting a security issue.