The AdminBolt team takes security issues seriously. We appreciate your efforts to responsibly disclose your findings.
Please DO NOT report security vulnerabilities through public GitHub issues.
Instead, please report them via email to:
- Email: contact@adminbolt.com
Please include the following information:
- Type of vulnerability
- Full paths of source file(s) related to the issue
- Location of the affected source code (tag/branch/commit or direct URL)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Initial Response: Within 24 hours
- Status Update: Within 72 hours
- Resolution: Varies based on severity
Security updates are released as soon as possible after a vulnerability is confirmed. We follow this process:
- Vulnerability is reported and confirmed
- Fix is developed and tested
- Security advisory is prepared
- Update is released to all users
- Public disclosure after users have time to update
AdminBolt includes several built-in security features:
- Two-factor authentication (2FA)
- Password strength enforcement
- Brute-force protection
- Session management
- IP-based access control
- Built-in firewall management
- DDoS protection integration
- SSL/TLS certificate automation
- Security headers configuration
- Input validation and sanitization
- SQL injection prevention
- XSS protection
- CSRF protection
- Security headers (CSP, HSTS, etc.)
- Regular security updates
- File integrity monitoring
- Malware scanning
- Security audit logging
- Rootkit detection
- Keep AdminBolt Updated: Always run the latest version
- Use Strong Passwords: Enforce strong password policies
- Enable 2FA: Require two-factor authentication
- Regular Backups: Maintain automated backup schedules
- Monitor Logs: Review security logs regularly
- Limit Access: Use principle of least privilege
- Firewall Rules: Configure restrictive firewall rules
- SSL/TLS: Use HTTPS for all connections
- Strong Passwords: Use unique, complex passwords
- Enable 2FA: Protect your account with two-factor authentication
- Secure FTP: Use SFTP instead of FTP
- Regular Updates: Keep your applications updated
- Backup Data: Regularly backup your data
- Monitor Activity: Review account activity logs
After installation, complete this security checklist:
- Change default admin password
- Enable two-factor authentication
- Configure firewall rules
- Enable SSL/TLS certificates
- Set up automated backups
- Configure security notifications
- Review and adjust file permissions
- Disable unnecessary services
- Configure fail2ban or similar
- Set up log monitoring
- We follow a coordinated disclosure approach
- Public disclosure occurs after fix is deployed
- Credit is given to reporters (if desired)
- Severity ratings follow CVSS v3.1
Last Updated: October 2025