Security policy
Last updated: October 3, 2026
Security is part of how we build, not a plugin we install afterwards. This page explains how eterni.tech is protected and how to report a vulnerability.
How this website is built
- A custom theme and a single custom plugin. No page builder, no third-party plugins, so there’s far less code to attack.
- HTTPS everywhere with HSTS, a strict Content-Security-Policy, and modern security headers.
- Rate-limited sign-in with lockouts, optional two-factor authentication, and an audit log of sign-ins and privilege changes.
- Public user enumeration, XML-RPC and file editing from the dashboard are disabled.
- The website-check tool only fetches public addresses, and pins each request to the address it verified.
- Regular backups and automatic security updates for WordPress core.
Reporting a vulnerability
If you believe you’ve found a security issue in eterni.tech or in a website we maintain, please email [email protected] with “Security” in the subject line. Include the URL, what you found, and steps to reproduce it.
- Please give us reasonable time to fix the issue before sharing it publicly.
- Don’t access or change data that isn’t yours, don’t degrade the service for others, and don’t use social engineering or physical attacks.
- We won’t pursue legal action against good-faith research that follows these guidelines, and we’ll credit you if you’d like.
Our machine-readable contact details are at /.well-known/security.txt.
