Support
=======

## Before requesting help

Confirm the exact plugin version, WordPress version, PHP version, selected
profile, finding ID, status, confidence, coverage, and displayed limitation.
Try the same action once more only when the UI says it is safe to resume or
repeat. Keep the original report private.

Before the public WordPress.org release, use the contact form at
`https://wp-content.ru/contact/` or email `wordpress@320px.ru`. After release,
ordinary product questions may also use the official WordPress.org support
forum. Security issues must follow `SECURITY.md`, not a public forum.

## Safe diagnostic information

Share only the smallest information needed: plugin/WP/PHP versions, the profile,
the finding's machine ID, status, confidence, coverage, limitation, and a short
synthetic reproduction. Review every export before sending it.

Never send credentials, SSH keys, API keys, cookies, database dumps,
`wp-config.php`, `.env`, personal data, customer records, private source code,
server paths, or an unreviewed full report. The 320px team does not need SSH or
wp-admin credentials to explain a finding.

## Scope and limitations

Site Audit explains bounded evidence; it does not change the audited site. A
finding is not a guarantee of a defect, and a pass is not a certification of
security, SEO performance, accessibility, or legal compliance. `not_tested`
means the evidence boundary was incomplete and should not be treated as a pass.

When the plugin's optional review-request form is used, contact-only is the
default. The exact preview, consent, deletion link, and retention date govern
that one request. Opening the form or preparing the preview sends nothing.
