“When security risks in web services are discovered by independent security researchers who understand the severity of
the risk, they often lack the channels to disclose them properly. As a result, security issues may be left unreported.
security.txt
defines a standard to help organizations define the process for security researchers to disclose security
vulnerabilities securely.”
Adds the following routes to your October CMS website:
/security.txt
/.well-known/security.txt
Go to the Settings section and provide the required information.
PHP 7.4 or higher
composer require vdlp/oc-securitytxt-plugin
If you have any question about how to use this plugin, please don't hesitate to contact us at [email protected]. We're happy to help you. You can also visit the support forum and drop your questions/issues there.