Payment integrations handle business-critical workflows. Security-sensitive findings must be reported privately.
Do not open a public GitHub issue for a suspected vulnerability.
Preferred channels:
- GitHub Private Vulnerability Reporting, when enabled for this repository; or
- info@simplixi.com with subject
[Security] SimplixPay for UPayments.
Include only what is required to reproduce the issue. Never send live API keys, bearer tokens, full card data, customer unique/card tokens, token-identity secrets/provenance material, customer databases or unnecessary personal information. If a secret is directly involved, describe its role and coordinate a secure exchange method first.
- affected SimplixPay version or exact commit;
- WordPress/WooCommerce/PHP versions;
- checkout/HPOS/multilingual state where relevant;
- concise reproduction;
- impact and required privileges;
- minimal sanitized logs/stack traces;
- suggested remediation if available.
Allow reasonable time for validation, remediation and coordinated release. Public advisories/release notes will avoid operational detail that unnecessarily increases exploitation risk. Security fixes require the same exact-SHA review discipline as other payment-critical changes.