Security updates are provided for the latest stable release.
Reports affecting older versions are welcome, but fixes may be released only for the latest version. Users should upgrade before confirming whether an issue remains present.
Please report suspected vulnerabilities privately.
Security → Advisories → Report a vulnerability.Include when available:
The maintainers will make a best-effort attempt to:
Resolution timelines depend on severity, exploitability, complexity and maintainer availability. These targets are not a service-level agreement.
Please coordinate public disclosure with the maintainers so affected users have a reasonable opportunity to update or apply mitigations.
Confirmed reporters will receive credit unless they request anonymity.
This project uses PHPForge to automate security and quality checks, including:
These controls help reduce security risk and prevent regressions, but they do not guarantee the absence of vulnerabilities or replace manual review and responsible reporting.