We take the security of WikiForms seriously. If you find a security vulnerability, please do not open a public issue on GitHub. Instead, follow the reporting procedure below to help us protect the Wikimedia tool ecosystem.
We actively provide security patches for the following deployment instances:
| Version | Supported |
|---|---|
Live Production (wikiforms.toolforge.org) |
β Yes |
Main Branch (github/main) |
β Yes |
| Older Releases / Custom Forks | β No |
If you discover a vulnerability (e.g., SQL Injection in Laravel backend, XSS in React frontend, or API key exposures), please report it responsibly:
- Send an email with your findings to the repository maintainer or open a private security advisory on GitHub.
- Include detailed steps, payloads, or screenshots to reproduce the issue.
- As this tool is currently maintained by a volunteer developer, we will acknowledge your report as soon as possible and work diligently on a fix. We kindly ask for a reasonable coordinated disclosure timeline before the issue is discussed publicly.
Validated security researchers will be permanently recognized on our live Hall of Fame ledger.