The following versions of this project are currently receiving security updates:
| Version | Supported |
|---|---|
| 1.x.x | ✅ |
Please do not report security vulnerabilities through public GitHub issues, pull requests, or discussion threads.
Instead, use one of the following private channels:
- Email: security@wickedbyte.com
- Contact form: wickedbyte.com (use the website contact form and indicate that your message concerns a security matter)
We aim to acknowledge receipt of your report within 2 business days and will keep you informed as the issue is triaged and resolved.
- A clear description of the vulnerability and its potential impact
- The affected version(s) and component(s)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept code or a working exploit (if available)
- Any suggested mitigations or patches you have in mind
Once a report is received, we follow a coordinated disclosure process:
-
Acknowledgment — We confirm receipt within 2 business days and open a private channel with the reporter.
-
Triage — We reproduce the issue, assess its severity using CVSS, and assign an internal priority.
-
Remediation — We develop and test a fix. The timeline will vary with severity:
Severity Target patch timeline Critical 7 days High 14 days Medium 30 days Low 60 days -
Notification — Before public release, we share the draft advisory and fix with you for review.
-
Release & Advisory — The patched version is published and a security advisory is posted.
We appreciate the work of security researchers acting in good faith. If you report responsibly and do not exploit the issue beyond demonstration, we will not pursue legal action.
We prefer to receive reports in English.
This policy is maintained by WickedByte and applies to all open source projects published under this organization.