Editorial Policy
How WPDeeply verifies, corrects and labels its content.
WPDeeply publishes security claims about other people’s software. That obliges us to be careful, and to say what careful means.
Technical accuracy
- Vulnerability claims are verified against a local reproduction, or clearly attributed to the record that published them.
- Version numbers, affected ranges and patched versions are taken from primary sources — the vendor changelog, the CVE record, or the directory listing.
- Where we cannot confirm a detail such as a CVE identifier, we say so rather than guessing. Several disclosures in our own archive have no CVE, and the pages say that plainly.
Corrections
Corrections are made in place, and material corrections are noted on the page. We do not silently rewrite a published security claim. Report errors to triumphoid@proton.me.
Historical research and attribution
The 2020–2021 disclosures in this archive were researched by Slavco Mihajloski (mslavco). Preserving that credit is a condition of keeping those pages online, not a courtesy.
Sponsored content
- Sponsored articles are labelled as sponsored, in the article, at the top.
- Sponsors do not get to influence risk ratings, vulnerability coverage or plugin profiles. Those are generated from the rules on the methodology page.
- We decline sponsorships that require us to say a specific product is secure.
Affiliate relationships
Some outbound links to hosting and security products are affiliate links. See the affiliate disclosure. No affiliate relationship changes what a scan reports.
AI use
Drafting assistance is fine; unverified generated claims are not. Every technical assertion on this site is checked against a primary source before publication.