Thank you for your response, but standard template apologies and shifting responsibility do not resolve this issue or rebuild lost trust.
To address your points directly:
Email Communications & Accountability:
We log into your platform daily using our primary account email address—the exact same address where we regularly receive your promotional and transactional communications without issue. The "bounced email" or "unsubscribed" explanation simply does not hold up here. Rather than double-checking our contact details or offering to verify our email status in your system, you have passed the blame onto our deliverability.
Core Responsibility for Product Security:
As a software vendor, it is your fundamental obligation to deliver secure, well-tested code. While vulnerabilities can happen, the impact of a critical exploit falls squarely on the product provided. Relying on social media posts or pinned forum threads is not an acceptable substitute for direct, critical security notifications to active paid users.
Service & Support Gap:
It is telling that our web hosting provider—who is not responsible for your software—has been significantly more proactive and helpful in guiding us through this Joomla security crisis than your team has been.
What We Require Moving Forward:
Email Verification: Please manually check and confirm that our primary account email address is marked as active and deliverable for all critical security advisories in your system.
Immediate Site Status Update: Provide a clear timeline and status update on the file scan and cleanup currently underway on our site.
Preventative Action: Outline what concrete steps your team is taking to prevent similar critical vulnerabilities in your extensions moving forward.
We do not need generic copy-pasted responses. We need direct communication, technical accountability, and a clear path to getting our site safely restored.