Skip to content

Security: andersonsalas/expressionlab

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release (master branch) receives security updates:

Version Status
Latest release Supported
Older releases Unsupported

Reporting a Vulnerability

If you discover a security vulnerability or a way to bypass the execution guardrails in Expression Lab, please do not open a public GitHub issue.

Instead, please report it through one of the following private channels:

  1. GitHub Private Vulnerability Reporting (Recommended):
    Navigate to the Security Advisories tab and click "Report a vulnerability".
  2. Direct Email:
    Send an email to github@andersonsalas.com.

What to Include

To help us understand and resolve the issue quickly, please provide:

  • A description of the issue and potential impact.
  • Steps to reproduce it (including a minimal sample DSL query or configuration).
  • The environment where it was reproduced (PHP version, WordPress version, browser).

What to Expect

  • Acknowledgment: You will receive a response acknowledging receipt of your report within 48 hours.
  • Coordinated Fix: We will develop the fix privately and coordinate a release date with you before publishing an advisory or changelog entry.
  • Credit: If you wish, we will gladly credit your responsible disclosure in the release notes.

There aren't any published security advisories