Skip to content

Security: mdabdullahproplayer/PipraPay

Security

SECURITY.md

Security Policy

Supported Versions

The following versions of PipraPay currently receive security updates and patches.

Version Supported
Latest Stable Release
Previous Stable Release
Older Releases
Development / Beta Versions ⚠️ Best Effort

We strongly recommend running the latest stable release to receive security fixes and improvements.


Reporting a Vulnerability

The PipraPay team takes security seriously and appreciates responsible disclosure of vulnerabilities.

How to Report

If you discover a security vulnerability, please do not create a public GitHub issue.

Instead, report it privately by:

Please include:

  • A detailed description of the vulnerability
  • Steps to reproduce the issue
  • Potential impact
  • Screenshots, logs, or proof-of-concept code (if applicable)
  • Your contact information for follow-up questions

What to Expect

After receiving a report:

  1. We will acknowledge receipt of the report within 72 hours.
  2. We will investigate and validate the issue.
  3. We may contact you for additional information.
  4. Security fixes will be developed and released as quickly as possible.
  5. Once resolved, we may publicly acknowledge your contribution unless you prefer to remain anonymous.

Responsible Disclosure

Please give us reasonable time to investigate and resolve reported vulnerabilities before publicly disclosing them.

We ask that researchers:

  • Avoid accessing, modifying, or deleting user data.
  • Avoid actions that could negatively affect users or system availability.
  • Report vulnerabilities responsibly and in good faith.

Scope

This policy applies to:

  • PipraPay Core
  • Official PipraPay Plugins
  • Official PipraPay Mobile Applications
  • Official PipraPay APIs and Services

Third-party plugins, integrations, or modified distributions may have separate security policies and are not covered by this policy.

Thank you for helping keep the PipraPay ecosystem secure.

There aren't any published security advisories