Security fixes are applied to the latest published release in the current major version.
| Version | Supported |
|---|---|
| 1.1.x | Yes |
| 1.0.x | No |
Do not publish credentials, bot tokens, API keys, private URLs, customer data, database exports or complete production logs in a public issue.
When GitHub private vulnerability reporting is available for this repository, use Security → Report a vulnerability.
If private reporting is not available, open a public issue containing only a minimal, non-sensitive summary and request a private communication channel. Do not include exploit details or secrets in that issue.
A useful report should include:
- affected plugin version;
- WordPress and PHP versions;
- affected feature or request path;
- reproducible steps using non-sensitive sample data;
- expected security impact;
- any suggested mitigation.
Reports will be reviewed as time permits. Confirmed vulnerabilities will be fixed in the current supported release line and documented without exposing unnecessary operational details.