QuestPump

Security

Found a security problem in QuestPump? Please tell us privately first, so we can fix it before anyone misuses it.

This policy covers QuestPump by Pluxia GmbH, a Swiss company: the QuestPump add-on for World of Warcraft, QuestPump Helper for Mac and Windows, the QuestPump apps for iPhone, Apple Watch, Android and Wear OS, and this website. The game itself and other companies' services are out of scope.

Where to write

Please report it privately, never in a public issue:

What to include

Please test only on your own devices and accounts, send no one's personal or health data, and keep the problem private until a fix is out.

What you can expect

Supported versions

How the helper's releases are protected

What the helper exposes

The helper never runs as an administrator. On Windows two one-time steps, the firewall rule and the right to write into the game folder, each run one command as an administrator after the player accepts the Windows prompt, and uninstalling removes that firewall rule after one more prompt. Updates never ask for an administrator: where the player's Mac account cannot replace the helper's app, the helper says to download the new version instead.

Problems that are being exploited

If a problem in QuestPump is being actively exploited, Pluxia GmbH reports it to the EU's single reporting platform, as the EU Cyber Resilience Act asks (Article 14), and tells the people who use QuestPump what to do.

For tools: security.txt.