Only the latest released version of lvandi/php-crap-checker receives security fixes.
Please do not report security vulnerabilities through public GitHub issues.
You can report a vulnerability in one of two ways:
-
GitHub Security Advisories — use the Report a vulnerability link in the Security tab of this repository (preferred).
-
Email — send a message to
developer@holisoft.itwith the subject line[php-crap-checker] Security Vulnerability.
- A description of the vulnerability and its potential impact
- Steps to reproduce or a minimal proof-of-concept
- Affected versions (if known)
| Action | Target time |
|---|---|
| Initial acknowledgement | ≤ 72 hours |
| Triage and severity assessment | ≤ 7 days |
| Fix or mitigation | Depends on severity — critical issues are prioritised |
We will coordinate a disclosure date with you once a fix is ready. Public disclosure before a fix is available may put users at risk; we ask that you follow responsible disclosure practices.