Start trial

Ship more secure code, faster

Security and compliance platform for open-source vendors

managed vdp
we manage security for 1,134 plugins
Browse the full directory

Patchstack's managed VDP (mVDP) acts as an expert intermediary and streamlines vulnerability disclosure for plugin and theme developers.

Comparison mVDP by Patchstack In-house VDP
Cost Free Tools and staff (security analyst)
Implementation 15 minutes Process development takes time
Compliance Pre-built compliance with CRA, ISO/IEC 29147, GDPR in mind Requires expertise (compliance officer) and time to research legalities
Talent Patchstack runs the most active open-source bug bounty program and a top-tier triage team Security researchers are difficult to attract, motivate and manage
Threat Intelligence Continuous 24/7 processing of incoming data, along with intelligence from third-party data sources Additional operational burden and limited due to lack of monitoring in distributed software
Quality Fully filtered and valid reports with commentary from the triage team High percentage of false, incomplete and meaningless “beg bounty” reports
Vulnerability processing Patchstack is the worlds’ largest handler of vulnerability data (CNA) Obtaining a CNA status to disclose vulnerabilities requires resources
Disclosure and handling Patchstack manages legal complexities and coordinates disclosure via best industry practices Higher legal risks due to lack of expertise, and additional operational burden

Take your code security to the next level and partner with the leader in open-source security

Managed VDP

Free

No CC required

Unlimited

Security programs

Streamline your disclosure process to fix security vulnerabilities faster and comply with emerging regulations.

Start a managed VDP for free
  • 1 seat
  • Vulnerability validation
  • CVE coordination
  • Patch validation
  • AXP boost +25% to motivate researchers
  • Follow CRA, ISO/IEC 29147, GDPR guidelines
  • Embeddable reporting form
🚀 ⭐ 🌒

"We highly recommend Patchstack to other companies looking to enhance their security posture. For us, Patchstack is a true partner in our security efforts, and we're more than satisfied with their services."

Miriam Schwab's logo Miriam Schwab's avatar

Miriam Schwab

Head of WordPress Relations

for vendors

Security disclosure and CRA compliance with Patchstack

In Q4 2024, The Cyber Resilience Act (CRA) introduced obligatory software support and vulnerability disclosure guidelines for all commercial software with users in the European Union.

Patchstack solves this by acting as an expert intermediary and streamlines vulnerability disclosure for plugin and theme developers.

  • Vulnerability Disclosure Policy (VDP) template Check
  • A process to report security vulnerabilities Check
  • Document dependencies and libraries used Check
  • Share data with EU authorities Check
  • Notify users about vulnerability exploits Check
  • Provide security updates (separately) Patchstack helps with patch validation Check
In Q1 2025, Patchstack became the all-time largest security vulnerability processor (CNA). Statistics
Patchstack runs the most active open-source bug bounty and rewards researchers on your behalf. Bug Bounty
Patchstack provides paid manual full project code-review for WordPress plugin and theme developers. Auditing

What the FAQ

If you have questions, do not hesitate to reach out via mvdp@patchstack.com.

Start a free managed VDP and streamline vulnerability disclosure

Get started, it's free