Policy
Responsible disclosure
- We only write about vulnerabilities that are already public and have an official fix or mitigation.
- We verify only in isolated, disposable environments we build ourselves. We never test third-party systems.
- Pages never include exploit code, payloads or step-by-step reproduction; verification records describe the environment and the result only.
- For malicious-package incidents we analyse public data only and never download or run the malware.
- If a vendor or researcher thinks a page is wrong or discloses too much, email wenstudio.sunshine@gmail.com and we will reply within 72 hours.
- We do not accept undisclosed vulnerabilities. If you found a new one, report it to the vendor directly. We write about it only after it has been disclosed.
Corrections
To report a mistake, use "Report an error" at the bottom of any page or email wenstudio.sunshine@gmail.com. Once confirmed, we fix the page and update its date; major corrections are noted on the page.
Security of this site
If you find a security issue in plaincve.date itself, email wenstudio.sunshine@gmail.com and please do not publish it first. The contact is also listed in security.txt.
License
- Articles: CC BY 4.0. Republishing requires attribution and a link.
- Rules: MIT. Free for commercial and non-commercial use, with no warranty.
Ads, support and privacy
This site shows no ads, sets no cookies of its own and loads no third-party trackers. We accept voluntary support from readers (buy me a coffee on Ko-fi); it never influences the content or conclusions of any page.
Disclaimer
Content is for defensive and educational use only. It is compiled from public sources and may contain errors or be out of date; check the vendor's advisory before acting. We are not responsible for false positives or misses caused by our rules. Test in your own environment before deploying.