Only the latest release receives security fixes.
Please do not open a public issue for security problems. Relevant reports include sandbox escapes, unsafe handling of uploaded files (zip-slip, zip bombs, path traversal), and analyzer or web API vulnerabilities.
Email dabinayo@pm.me with the subject "PluginGuard security" and include:
- the affected version or commit;
- reproduction steps and the expected impact;
- a proposed fix, if you have one.
Do not include live credentials, player data or private files in the report.
You should receive an acknowledgement within seven days. Fix and disclosure timing will be agreed with you based on severity.