Skip to content
Boredgolem IMWA Lab

BOREDGOLEM / IMWA

Security

Report a vulnerability

Use the contact page with the subject Security report. Describe the affected version, impact, and safe reproduction steps. Do not include live credentials, raw customer records, or exploit a production account beyond the minimum needed to demonstrate the issue.

License security

IMWA uses domain-bound activations and Ed25519-signed leases. The private issuer key stays outside the WordPress webroot. Customer API keys and refresh credentials are never stored as readable values by the license database.

Operational boundaries

WordPress owns consent and control-plane state. High-frequency telemetry belongs in a separate queue and datastore. Site owners must keep HTTPS, WordPress, PHP, and all integrated plugins current.