| Version | Supported |
|---|---|
| 1.0.x | Yes |
| 0.x | No |
If you discover a security vulnerability in Mudrava RUM, please report it responsibly.
Do not open a public GitHub issue for security vulnerabilities.
Instead, email us directly at support@mudrava.com with:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We will acknowledge your report within 48 hours and aim to release a patch within 7 days of confirmation.
Mudrava RUM is built with a privacy-first, security-conscious architecture:
- No account identifiers - names, email addresses, IP addresses, and identity-profile data are not collected or stored
- Role labels only - a non-unique logged-in visitor role may be stored for role-based filtering and exclusion
- No cookies - session IDs use
sessionStorage(per-tab, cleared on close) - No external services - all data stays in your WordPress database; zero outbound requests
- Admin endpoints (
/logs,/stats,/send-report) requiremanage_optionscapability via WordPress REST API authentication - Public endpoint (
/collect) uses a custom nonce (X-MDVRM-Nonceheader) to prevent unauthorized submissions while avoiding WordPress core's premature cookie authentication checks - Settings forms use standard WordPress nonce verification (
wp_nonce_field/wp_verify_nonce)
- All database queries use
$wpdb->prepare()with parameterized placeholders - All user input is sanitized via
sanitize_text_field(),sanitize_email(),absint(),floatval() - All output is escaped via
esc_html(),esc_attr(),esc_url(),wp_json_encode() - Admin JavaScript uses safe DOM methods (
createElement,textContent) - noinnerHTMLwith dynamic data - Oversized ingestion payloads are rejected before JSON decoding
- Peer-address headers are honored only when the direct peer matches configured trusted proxies
- Rate-limit counters use time-bucketed, HMAC-hashed identities rather than storing client addresses
- Configurable maximum record count (FIFO eviction)
- Configurable retention period in days (automatic purge)
- Full cleanup on plugin uninstall (table drop, options delete, cron clear)
This policy applies to the Mudrava RUM WordPress plugin source code hosted at github.com/Mudrava/Mudrava-RUM.