Only the latest release (master branch) receives security updates:
| Version | Status |
|---|---|
| Latest release | Supported |
| Older releases | Unsupported |
If you discover a security vulnerability or a way to bypass the execution guardrails in Expression Lab, please do not open a public GitHub issue.
Instead, please report it through one of the following private channels:
- GitHub Private Vulnerability Reporting (Recommended):
Navigate to the Security Advisories tab and click "Report a vulnerability". - Direct Email:
Send an email to github@andersonsalas.com.
To help us understand and resolve the issue quickly, please provide:
- A description of the issue and potential impact.
- Steps to reproduce it (including a minimal sample DSL query or configuration).
- The environment where it was reproduced (PHP version, WordPress version, browser).
- Acknowledgment: You will receive a response acknowledging receipt of your report within 48 hours.
- Coordinated Fix: We will develop the fix privately and coordinate a release date with you before publishing an advisory or changelog entry.
- Credit: If you wish, we will gladly credit your responsible disclosure in the release notes.