InterMix

Security Policy

Supported Versions

Security updates are provided for the latest stable release.

Reports affecting older versions are welcome, but fixes may be released only for the latest version. Users should upgrade before confirming whether an issue remains present.

Reporting a Vulnerability

Please report suspected vulnerabilities privately.

  1. Go to SecurityAdvisoriesReport a vulnerability.
  2. If private vulnerability reporting is unavailable, open a public issue requesting a private security contact.
  3. Do not include vulnerability details in that issue or disclose them through public issues, discussions, pull requests or other public channels.

Include when available:

Response and Disclosure

The maintainers will make a best-effort attempt to:

Resolution timelines depend on severity, exploitability, complexity and maintainer availability. These targets are not a service-level agreement.

Please coordinate public disclosure with the maintainers so affected users have a reasonable opportunity to update or apply mitigations.

Confirmed reporters will receive credit unless they request anonymity.

PHPForge Security Controls

This project uses PHPForge to automate security and quality checks, including:

These controls help reduce security risk and prevent regressions, but they do not guarantee the absence of vulnerabilities or replace manual review and responsible reporting.