Security reporting
Report a suspected security issue
Last updated: 6 August 2026
If you believe a Wood Websites-owned public service has a security weakness, please report it directly to Joseph Thomas Wood at joe@woodwebsites.uk. A clear, responsible report is welcome.
What is in scope
This reporting route covers public services owned and operated by Wood Websites, including:
woodwebsites.ukand its public pagesbrief.woodwebsites.ukstatus.woodwebsites.uk
Client websites, client domains, client email systems, third-party provider accounts and any system not owned by Wood Websites are out of scope unless you have separate written authorisation from its owner.
Please test safely
Do not access, retain, alter or delete another person’s information. Do not disrupt availability, send high-volume traffic, attempt social engineering, upload malware, test physical security or use a finding to gain further access. Stop if testing could affect a customer, another user or a live service.
Please do not publish a suspected issue before there has been a reasonable opportunity to understand and address it. This page does not grant permission to break the law, access third-party systems or exceed the limited public scope above.
What to include
A useful first report includes:
- the affected service and exact URL;
- the date, time and time zone when you observed the issue;
- what you expected and what happened instead;
- concise steps that reproduce the issue without causing harm; and
- your preferred contact details, if you want a reply.
Do not email passwords, recovery codes, API tokens, private keys, payment details, personal information or unnecessary copies of private data. If sensitive evidence is genuinely needed, describe it first so a suitable transfer route can be agreed.
How reports are handled
Joe reviews reports personally, confirms the affected service and decides what containment, provider escalation or remediation is appropriate. The time needed depends on the issue and any service providers involved, so this page does not promise a fixed acknowledgement or resolution deadline.
There is currently no public bug-bounty programme. Please do not incur costs or undertake extended testing in expectation of payment.
Looking for an outage update?
Availability notices and current Wood Websites service information belong on the separate status page.