Please follow the guidelines below if you believe you have discovered a vulnerability in this project.
Caution
Please do not open GitHub issues for security vulnerabilities!
Please use GitHub's private vulnerability reporting. Open the Security tab and click "Report a vulnerability", or go straight to the report form.
Your report should include the following details:
- The exact version or version range that you analysed.
- The PHP version that you used for your analysis.
- A step-by-step explanation of how to exploit the potential vulnerability.
One person maintains this project in their spare time. Expect a first reply within 14 days. You will hear whether the report is accepted and when a fix is planned. No bounties are offered.