LMRuntime.com / Public page

Security

Responsible disclosure, hosting notes, and public information boundaries for the website and runtime.

The public site removes package manifests, source counts, candidate hashes, and deep internal ledgers from public-facing copy.

Public disclosure

Public pages describe what the runtime does and what is not yet claimed. Detailed package maps, source identifiers, manifest counts, internal memory files, and candidate hashes belong in private project documentation or in a public repository only after a release decision.

Hosting checks

  • Force HTTPS and redirect HTTP to HTTPS after TLS is stable.
  • Check for 502 errors from PHP-FPM, reverse proxy, or origin-server configuration.
  • Add security headers at the server layer, not only in the theme.
  • Keep WordPress core, plugins, and PHP current.

Privacy

The theme does not include tracking pixels, external fonts, CDN scripts, or third-party analytics. Privacy-minimized aggregate counts for link-support actions are disabled by default and store no visitor identity when explicitly enabled. If forms, cookies, demos, or broader measurement are added later, the privacy notice should be updated before launch.

Contact and corrections

For security reports, corrections, or questions about disclosure boundaries, email mike@ns12.com or use the Contact page. Do not post exploit details publicly before the report is acknowledged. The document-root package publishes the canonical /.well-known/security.txt record.