Wordfence Vulnerability Management Portal — Terms and Conditions
The Vulnerability Management Portal is provided by Defiant, Inc. (“Company”). These Vulnerability Management
Portal Terms and Conditions (“Portal Terms”) govern your access to and use of the Vulnerability Management
Portal (the “Portal”) and are incorporated by reference into, and made part of, the Wordfence Terms of
Service (the “Terms of Service”) available at https://www.wordfence.com/terms-of-service/.
Capitalized terms used but not defined in these Portal Terms have the meanings given in the Terms of Service.
To the extent a conflict exists between these Portal Terms and the Terms of Service, these Portal Terms
control solely with respect to the Portal.
WORDFENCE INTELLIGENCE IS OFFERED AT NO FEE.
1. Service Description
The Portal is an online interface made available at
https://www.wordfence.com/threat-intel/vendor/portal/
through which verified WordPress software vendors (“Vendors”) may:
- register and verify ownership of their software projects;
- review Active Vulnerabilities (vulnerabilities submitted through the Wordfence Bug Bounty Program,
discovered by Company, or sourced from third-party databases) before, or after, public disclosure;
- review Historical Vulnerabilities that have been remediated or otherwise published;
- upload proposed patches or final fixes for Company’s limited review;
- delegate limited (view and manage vulnerability reports) access to additional personnel; and
- configure email, webhook, or Slack notifications regarding vulnerability status.
For purposes of these Portal Terms, the “Service” means the Portal and all vulnerability information,
reports, notifications, and patch-review functionality made available through it.
2. Access, Registration, and Verification
-
Eligibility.
Access is limited to Vendors that:
- own or control one or more WordPress-related software products
- successfully complete Company’s vendor verification process, and
- maintain an active account with the Service.
-
Verification Methods.
Verification may be completed
- by uploading a unique text file to the domain present in the software package’s Plugin URI or
Theme URI header, that will periodically be checked by our servers until the software’s
ownership is verified or
- through alternative manual methods designated by Company. You represent and warrant that any
materials submitted for verification are accurate, complete, and lawfully provided.
-
Account Security.
You are responsible for all activity occurring under your Portal account, including activity of Team
Members you invite. You must promptly notify Company of any unauthorized use or security breach.
3. License Grant and Use Restrictions
-
License. Subject to continuous compliance with these Portal Terms and the Terms of
Service, Company grants you a limited, non-exclusive, non-transferable, revocable right to access and
use the Service internally for the purpose of assessing, triaging, and remediating vulnerabilities in
your verified software.
-
Restrictions. Except as expressly permitted, you must not
- disclose, publish, or redistribute any non-public vulnerability information obtained through
the Service,
- use the Service to benchmark or compete with Company, or
- reverse-engineer, interfere with, or circumvent any security measures of the Service.
-
Reservation of Rights. All rights not expressly granted are reserved by Company.
4. Vendor Obligations
-
Patch Submissions. If you upload a patch or other fix, you:
- grant Company a non-exclusive, royalty-free license to test, review, and evaluate the patch
solely for vulnerability remediation;
- acknowledge that Company’s review is limited in scope and does not constitute a certification,
guarantee, or warranty that the vulnerability is fully remediated; and
- remain solely responsible for the quality, security, and deployment of any patch.
- Delegated Access. You may invite additional users (“Team Members”) to view vulnerability reports related
to your verified software. Team Members are required to have an existing Wordfence account or create a
new account to access the Services. You are responsible for each Delegate’s compliance with these Portal
Terms and the Terms of Service.
- Confidentiality. Non-public vulnerability data and reports are Company Confidential Information. You may
use such data solely to remediate vulnerabilities in your verified software and must protect it using at
least the same degree of care you use for your own confidential information (and no less than reasonable
care).
5. Disclaimers; No Warranty for Patch Review
IN ADDITION TO THE DISCLAIMERS SET FORTH IN THE TERMS OF SERVICE, COMPANY PROVIDES ANY PATCH REVIEW OR
FEEDBACK ON AN “AS IS,” “AS AVAILABLE” BASIS WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. COMPANY
SPECIFICALLY DISCLAIMS ANY WARRANTY THAT A PATCH WILL FULLY RESOLVE OR NOT INTRODUCE VULNERABILITIES,
DEFECTS, OR OTHER ISSUES. YOU ARE SOLELY RESPONSIBLE FOR INDEPENDENT TESTING, VALIDATION, AND DEPLOYMENT
OF ANY REMEDIATION.
6. Suspension and Termination
Company may suspend or terminate your access to the Portal immediately
- for violation of these Portal Terms,
- if verification fails or is withdrawn, or
- to protect the security or integrity of the Service, the Wordfence Bug Bounty Program, or affected users.
Sections 3 through 8 survive any termination.
7. Miscellaneous
- Modification of Portal Terms. Company may update these Portal Terms in accordance with the “Changes to
These Terms” provision of the Terms of Service.
- Third-Party Beneficiaries. There are no third-party beneficiaries to these Portal Terms.
- Entire Agreement. These Portal Terms, together with the Terms of Service, constitute the entire agreement
between you and Company regarding the Portal and supersede any prior agreements or understandings on
that subject.
- Conflicts. If any provision of these Portal Terms is held invalid or unenforceable, the remaining
provisions remain in full force, and the invalid provision will be interpreted to fulfill its intent to
the maximum extent permitted.