Skip to content

Security: NXT-WEBSITE/nxt-cloud-chat

SECURITY.md

Security Policy

Thank you for helping keep NXT Cloud Chat and its users secure.

We take security issues seriously and appreciate responsible disclosure from the community.


Supported Versions

Security updates are generally provided for the latest stable release of NXT Cloud Chat.

Version Supported
1.0.x ✅
Older versions ❌

Please update to the latest available version before reporting issues whenever possible.


Reporting a Vulnerability

If you discover a security vulnerability in NXT Cloud Chat, please report it privately.

📧 Email: support@nxtwebsite.com

Please include:

  • A clear description of the issue
  • Steps to reproduce the vulnerability
  • Affected plugin version
  • Any proof-of-concept details or screenshots (if available)
  • Suggested mitigation or fix (optional)

Responsible Disclosure

Please do not publicly disclose security vulnerabilities before a fix is available.

This helps protect WordPress site owners and users from active exploitation while a patch is being prepared and released.

We will make reasonable efforts to respond to valid security reports as quickly as possible.


Scope

This security policy applies to:

  • NXT Cloud Chat (Free)
  • Official NXT Cloud Chat Pro integrations and compatibility layers

Third-party plugins, custom modifications, hosting environments, or external services are outside the direct scope of this policy.


External Services

NXT Cloud Chat integrates with the official WhatsApp Business Platform (WhatsApp Cloud API) provided by Meta Platforms, Inc.

Issues related to Meta infrastructure or WhatsApp platform availability should be reported directly to Meta where applicable.


Open Source Security

NXT Cloud Chat is an open-source WordPress plugin. Community reviews, responsible disclosures, and security-related feedback are always welcome.

Thank you for helping improve the security and reliability of the project.

There aren't any published security advisories