Skip to content
Contact

Talk to a human
who’s seen your problem.

Tell us which side you're on, running sites, or rating organisations, and you'll get someone who actually works on that product.

Who to talk to

Pick the right route

The plugin

Plugin sales & support

Installation help, scan questions, agency licences.

Email plugin team

Enterprise

Ratings & demos

Free organisation rating, portfolio quotes, methodology walkthroughs.

Book a demo

Security

Vulnerability disclosure

Found something in our products? We run a coordinated disclosure programme and respond fast.

Report a vulnerability

Message us

Prefer email? Reach us directly at [email protected], we answer within one working day.

Before you contact anyone

Four checks that resolve most problems faster than a ticket

Run an on-demand scan first, scoped to what changed. If you updated a plugin, scan plugins only; if you restored a backup, scan core only. A scoped scan finishes in a fraction of the time of a full one and answers the question you actually have.

Read the findings list rather than the summary grade. The grade tells you there is a problem; the findings tell you what and where, with file paths and severity.

If the site behaves oddly for visitors but not for you, redirects your customers report and you cannot reproduce, that pattern is characteristic of a conditional payload targeting mobile or search-referred traffic. Run a database scan, because that is usually where it lives.

If a security setting broke something, the toggle that changed it states what it affects. Reverting is immediate, and identifying which control caused it is more useful than disabling everything.

What to include

Making a support request answerable in one round

The difference between a resolution today and a three-day exchange is almost always the first message. What helps: your WordPress and PHP versions, the plugin version, whether the site is Multisite, the exact finding or error text rather than a paraphrase, and what changed immediately before the problem started.

That last one resolves more cases than anything else. An update, a new plugin, a host migration, a DNS change, an expired certificate: the timeline usually contains the answer, and it is the piece nobody can reconstruct from outside.

If the issue is a finding you believe is wrong, say why. A false positive with reasoning attached gets investigated properly and often improves detection for everyone; a bare assertion is much harder to act on.

Where to go

Which channel suits which problem

For a suspected security vulnerability in the plugin itself, use the vulnerability disclosure process rather than a support channel. It routes to the research team directly and does not sit in a public queue while unpatched.

For a bug, something that does not work as documented, the bug report route captures the reproduction detail that makes a fix possible. For questions about what a feature does or which plan includes it, the FAQ and feature pages answer most of them faster than we can.

For an active compromise on a Pro or Agency licence, say so in the first line. Incident traffic is triaged ahead of general support, and Agency licences carry a four-hour SLA with an escalation path to the RedSecLabs research team.

FAQ

Common questions

My site redirects visitors but looks fine to me. What is happening?

That pattern usually means a conditional payload firing for mobile or search-referred traffic and staying quiet for direct visits. Run a database scan, that is typically where it lives, and it is why filesystem-only cleanups get reinfected.

What should I include in a support request?

WordPress and PHP versions, plugin version, whether the site is Multisite, the exact finding or error text, and what changed immediately before the problem started. That last one resolves more cases than anything else.

I think a finding is a false positive. What do I do?

Report it with your reasoning. A false positive with an explanation gets investigated properly and often improves detection for everyone.

A security setting broke my site. How do I undo it?

Every toggle states what it changes and what depends on it, and all are individually reversible. Revert the specific one rather than disabling everything.

How fast is support?

General support is best-effort. Agency licences carry a four-hour SLA and an escalation path to the RedSecLabs research team. If you have an active compromise, say so in the first line, incident traffic is triaged ahead of general questions.

Where do I report a vulnerability in the plugin itself?

Through the vulnerability disclosure process rather than a support channel, so it reaches the research team directly and does not sit in a public queue while unpatched.