Security policy
Last updated: September 30, 2026
If you found a security problem in our software or website, we want to hear about it. This page explains how to report it and what you can expect from us.
Scope
This policy covers:
- the TrazoForms plugin, in its Free and Pro versions;
- the twodigits.studio website.
These are out of scope:
- third-party services, such as Freemius, WordPress.org and Cloudflare: please report problems there to their own teams;
- social engineering, such as phishing or pretexting against us or our customers;
- denial-of-service attacks and anything meant to overload a service;
- tests against websites that belong to other people.
How to report
Write to security@twodigits.studio with:
- the steps to reproduce the problem;
- the affected version of the plugin, or the address of the affected page;
- a proof of concept, if you can share one.
Please do not disclose the problem publicly until a fix is available.
What to expect
- We aim to acknowledge your report within 5 business days.
- We will tell you when a fix is available.
- If you would like public credit for the report, tell us and we will thank you by name once the fix is out. If you prefer to stay anonymous, we will respect that.
We do not run a bug bounty program and we do not offer rewards.
Coordinated disclosure
As a reference, we suggest waiting up to 90 days from your report before publishing the details, so we have time to fix the problem and let people update. If you think a different date makes more sense, tell us; we are happy to agree on one.
Testing safely
Please test only on installations that you own. Do not access, change or delete data that is not yours.
WordPress.org
Security reports about plugins in WordPress.org can also be sent to security@wordpress.org. We ask that you tell us first, at the address above.