Wordfence Vulnerability Management Portal — Terms and Conditions

The Vulnerability Management Portal is provided by Defiant, Inc. (“Company”). These Vulnerability Management Portal Terms and Conditions (“Portal Terms”) govern your access to and use of the Vulnerability Management Portal (the “Portal”) and are incorporated by reference into, and made part of, the Wordfence Terms of Service (the “Terms of Service”) available at https://www.wordfence.com/terms-of-service/. Capitalized terms used but not defined in these Portal Terms have the meanings given in the Terms of Service.

To the extent a conflict exists between these Portal Terms and the Terms of Service, these Portal Terms control solely with respect to the Portal.

WORDFENCE INTELLIGENCE IS OFFERED AT NO FEE.

1. Service Description

The Portal is an online interface made available at https://www.wordfence.com/threat-intel/vendor/portal/ through which verified WordPress software vendors (“Vendors”) may:

  • register and verify ownership of their software projects;
  • review Active Vulnerabilities (vulnerabilities submitted through the Wordfence Bug Bounty Program, discovered by Company, or sourced from third-party databases) before, or after, public disclosure;
  • review Historical Vulnerabilities that have been remediated or otherwise published;
  • upload proposed patches or final fixes for Company’s limited review;
  • delegate limited (view and manage vulnerability reports) access to additional personnel; and
  • configure email, webhook, or Slack notifications regarding vulnerability status.

For purposes of these Portal Terms, the “Service” means the Portal and all vulnerability information, reports, notifications, and patch-review functionality made available through it.

2. Access, Registration, and Verification

  1. Eligibility. Access is limited to Vendors that:
    1. own or control one or more WordPress-related software products
    2. successfully complete Company’s vendor verification process, and
    3. maintain an active account with the Service.
  2. Verification Methods. Verification may be completed
    1. by uploading a unique text file to the domain present in the software package’s Plugin URI or Theme URI header, that will periodically be checked by our servers until the software’s ownership is verified or
    2. through alternative manual methods designated by Company. You represent and warrant that any materials submitted for verification are accurate, complete, and lawfully provided.
  3. Account Security. You are responsible for all activity occurring under your Portal account, including activity of Team Members you invite. You must promptly notify Company of any unauthorized use or security breach.

3. License Grant and Use Restrictions

  1. License. Subject to continuous compliance with these Portal Terms and the Terms of Service, Company grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Service internally for the purpose of assessing, triaging, and remediating vulnerabilities in your verified software.
  2. Restrictions. Except as expressly permitted, you must not
    1. disclose, publish, or redistribute any non-public vulnerability information obtained through the Service,
    2. use the Service to benchmark or compete with Company, or
    3. reverse-engineer, interfere with, or circumvent any security measures of the Service.
  3. Reservation of Rights. All rights not expressly granted are reserved by Company.

4. Vendor Obligations

  1. Patch Submissions. If you upload a patch or other fix, you:
    • grant Company a non-exclusive, royalty-free license to test, review, and evaluate the patch solely for vulnerability remediation;
    • acknowledge that Company’s review is limited in scope and does not constitute a certification, guarantee, or warranty that the vulnerability is fully remediated; and
    • remain solely responsible for the quality, security, and deployment of any patch.
  2. Delegated Access. You may invite additional users (“Team Members”) to view vulnerability reports related to your verified software. Team Members are required to have an existing Wordfence account or create a new account to access the Services. You are responsible for each Delegate’s compliance with these Portal Terms and the Terms of Service.
  3. Confidentiality. Non-public vulnerability data and reports are Company Confidential Information. You may use such data solely to remediate vulnerabilities in your verified software and must protect it using at least the same degree of care you use for your own confidential information (and no less than reasonable care).

5. Disclaimers; No Warranty for Patch Review

IN ADDITION TO THE DISCLAIMERS SET FORTH IN THE TERMS OF SERVICE, COMPANY PROVIDES ANY PATCH REVIEW OR FEEDBACK ON AN “AS IS,” “AS AVAILABLE” BASIS WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. COMPANY SPECIFICALLY DISCLAIMS ANY WARRANTY THAT A PATCH WILL FULLY RESOLVE OR NOT INTRODUCE VULNERABILITIES, DEFECTS, OR OTHER ISSUES. YOU ARE SOLELY RESPONSIBLE FOR INDEPENDENT TESTING, VALIDATION, AND DEPLOYMENT OF ANY REMEDIATION.

6. Suspension and Termination

Company may suspend or terminate your access to the Portal immediately

  1. for violation of these Portal Terms,
  2. if verification fails or is withdrawn, or
  3. to protect the security or integrity of the Service, the Wordfence Bug Bounty Program, or affected users. Sections 3 through 8 survive any termination.

7. Miscellaneous

  1. Modification of Portal Terms. Company may update these Portal Terms in accordance with the “Changes to These Terms” provision of the Terms of Service.
  2. Third-Party Beneficiaries. There are no third-party beneficiaries to these Portal Terms.
  3. Entire Agreement. These Portal Terms, together with the Terms of Service, constitute the entire agreement between you and Company regarding the Portal and supersede any prior agreements or understandings on that subject.
  4. Conflicts. If any provision of these Portal Terms is held invalid or unenforceable, the remaining provisions remain in full force, and the invalid provision will be interpreted to fulfill its intent to the maximum extent permitted.

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation