| Version | Supported |
|---|---|
| 1.0.x | ✓ |
| Earlier / unofficial builds |
Please use GitHub's Report a vulnerability private security-advisory flow for this repository. Do not open a public issue for:
- permission or authorization bypasses;
- export path traversal;
- unbounded work or denial-of-service paths;
- unsafe asynchronous Bukkit access;
- malicious MiniMessage/config behavior;
- dependency or release-pipeline compromise.
Include reproduction steps, affected version, expected impact, and any proposed fix. Do not include live server credentials, player data, private world files, or access tokens.
You should receive an acknowledgement within seven days. A fix and disclosure timeline will be coordinated based on severity.