Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

Other uncategorised cookies are those that are being analysed and have not been classified into a category as yet.

Skip to content

Adding software to mVDP

Patchstack accepts all WordPress software (plugins and themes) to be added to its mVDP directory. Here’s a process of listing your first software:

  1. Log in to mVDP platform: vdp.patchstack.com
  2. Click the green + Start new button
  3. Fill the form as shown below
  4. Add a VDP disclaimer to your software readme.txt file, or security.md in GitHub

Note that if you maintain separate software for free and paid licenses, you will have to add these as completely separate entries.

  1. Pick if you are submitting a plugin or a theme
  2. Pick, if it’s a free software, or is it a premium-licensed software. You can also choose Both, if you cover both plans in one software (also known as a freemium plugin)
  3. Software name - type the name of this software. This is how it will appear in Patchstack VDP directory and in the vulnerability database
  4. Software URL - preffered is the software repository URL. If the software is not in WordPress repository, enter any URL that takes to your software website
  5. Product slug - type a slug that you’d like to be indentified with in Patchstack VDP listing and database entries
  6. Software description - Write a short description, which will be shown in Patchstack VDP listing
  7. Dependencies - Write down all the third party software that your software is dependent on
  8. Secondary email - If you’d like to receive sensitive information about vulnerabilities to another email, you can write down your secondary email
  9. Upload software icon - This icon will be shown in Patchstack VDP directory and in the vulnerability database
  10. Upload source code - If your plugin is not available in public repository, you should upload the source code for us to view

Having filled up the form, click Start program

After submitting the form, you’ll be taken to your added software page. This page will show all the vulnerability and reports statistics about your software in the future.

Before Patchstack can validate your software, you will have to add a VDP disclaimer to your software readme.txt or security.md file in GitHub. The disclaimer can be copied, by clicking the Copy disclaimer for… button.

If you don’t have your project present on the WordPress repository, please e-mail us for verification at triage@patchstack.com

Adding a disclaimer on different platforms

Section titled “Adding a disclaimer on different platforms”

Depending on the platform you are using to host you software, you will have to add the VDP disclaimer in different places. Here are some best practices for how to do it.

You should add the disclaimer to your readme.txt file. The most common place is to add it add it to FAQ section.

You should add the disclaimer to your security.md and the readme.md file. If you don’t have those files, you can create them in the root of your repository.

You should add the disclaimer either to the main description of your component or add it to the support tab.

All websites are different, so there is no one-size-fits-all solution. However we recommend createing a dedicated page for security (e.g. security or report security issues) and adding the VDP disclaimer there. Next, you should link to this page from the footer of your website, so that it is easy to find.

If you have more components, you can put all the disclaimers on that page.

This is an example disclaimer, do not paste it to your software, as it includes an example link. You should copy the disclaimer straight from the mVDP platform by clicking the Copy disclaimer for… button.

= How can I report security bugs? =
You can report security bugs through the Patchstack Vulnerability Disclosure
Program. The Patchstack team help validate, triage and handle any security
vulnerabilities.
[Report a security vulnerability.](https://patchstack.com/database/vdp/your-software-slug)
1