BOREDGOLEM / IMWA
Security
Report a vulnerability
Use the contact page with the subject Security report. Describe the affected version, impact, and safe reproduction steps. Do not include live credentials, raw customer records, or exploit a production account beyond the minimum needed to demonstrate the issue.
License security
IMWA uses domain-bound activations and Ed25519-signed leases. The private issuer key stays outside the WordPress webroot. Customer API keys and refresh credentials are never stored as readable values by the license database.
Operational boundaries
WordPress owns consent and control-plane state. High-frequency telemetry belongs in a separate queue and datastore. Site owners must keep HTTPS, WordPress, PHP, and all integrated plugins current.