What is the difference between VDP and mVDP?

VDP stands for Vulnerability Disclosure Program which is usually self-managed. mVDP stands for managed Vulnerability Disclosure Program. This means that Patchstack processes all the vulnerability reports for you, rejects the false ones, provides additional information if needed, and helps validate the patches before release — making it the much more comfortable option.

Managed VDP

Free No CC required Unlimited

  • 1 seat
  • Vulnerability validation
  • CVE coordination
  • Patch validation
  • AXP boost +25% to motivate researchers
  • Follow CRA, ISO/IEC 29147, GDPR guidelines
  • Embeddable reporting form

Patchstack's managed VDP (mVDP) acts as an expert intermediary and streamlines vulnerability disclosure for plugin and theme developers.

Comparison mVDP by Patchstack In-house VDP
Cost Free Tools and staff (security analyst)
Implementation 15 minutes Process development takes time
Compliance Pre-built compliance with CRA, ISO/IEC 29147, GDPR in mind Requires expertise (compliance officer) and time to research legalities
Talent Patchstack runs the most active open-source bug bounty program and a top-tier triage team Security researchers are difficult to attract, motivate and manage
Threat Intelligence Continuous 24/7 processing of incoming data, along with intelligence from third-party data sources Additional operational burden and limited due to lack of monitoring in distributed software
Quality Fully filtered and valid reports with commentary from the triage team High percentage of false, incomplete and meaningless “beg bounty” reports
Vulnerability processing Patchstack is the worlds’ largest handler of vulnerability data (CNA) Obtaining a CNA status to disclose vulnerabilities requires resources
Disclosure and handling Patchstack manages legal complexities and coordinates disclosure via best industry practices Higher legal risks due to lack of expertise, and additional operational burden

Security disclosure and CRA compliance with Patchstack

In Q4 2024, The Cyber Resilience Act (CRA) introduced obligatory software support and vulnerability disclosure guidelines for all commercial software with users in the European Union.

Patchstack helps with patch validation.

What if I got a report from 3rd party?

We ask vendors to share those reports with us so we can validate them on our end and provide additional technical information on how to fix the issue. This is a great way to avoid duplicates and collisions in reports and the CVE database.

What happens if I ignore or reject a report?

The vulnerability will be disclosed 30 days after the report is sent to the vendor with the status "unfixed" and alerts sent to all Patchstack Vulnerability Database and partners who leverage our API. Vulnerabilities must be fixed, and there's no way to avoid disclosure as it's not related to mVDP membership.

Can I have multiple VDP programs?

Yes, it's possible, but we still ask for the information you're getting from other VDP programs you're using. We recommend using only one VDP program to avoid confusion and misinformation.

Do I need to fix low-priority vulnerabilities that cannot be exploited?

These are still vulnerabilities and can be used in a chained attack vector. We provide patch priority recommendations for users, but vendors must patch any vulnerability within 30 days of receiving the report.

What are the benefits to me as a developer/vendor?

Having a VDP security program is a signal to your users that you take security seriously and your software is trustworthy. Easy reporting motivates more security researchers to look for vulnerabilities and report them via the Patchstack Bug Bounty program to help make your software better and safer.

Will you check my software for security issues once I join the program?

Yes! We pay security researchers to check your free (and premium) plugins and themes.