We release patches for security vulnerabilities in the following versions:
| Version | Supported |
|---|---|
| 0.x.x | ✅ |
We take the security of A Plus+ seriously. If you believe you have found a security vulnerability, please report it to us as described below.
- Open a public GitHub issue
- Disclose the vulnerability publicly before it has been addressed
- Email us directly at: mhamed.saad.ibrahim@gmail.com
- Include in your report:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact
- Suggested fix (if any)
- Acknowledgment: We will acknowledge receipt of your report within 48 hours
- Updates: We will keep you informed about our progress
- Resolution: We aim to resolve critical issues within 7 days
- Credit: With your permission, we will credit you in our CHANGELOG
-
Never commit sensitive data:
- API keys
- Passwords
- Private keys
- Access tokens
.envfiles
-
Use environment variables:
- Store all secrets in
.env(excluded from Git) - Use
.env.exampleas a template - Never hardcode credentials
- Store all secrets in
-
Keep dependencies updated:
- Regularly run
npm audit - Update vulnerable packages promptly
- Review security advisories
- Regularly run
-
Follow secure coding practices:
- Validate all user input
- Sanitize data before database queries
- Use HTTPS for all external requests
- Implement proper authentication & authorization
-
Keep your installation secure:
- Use strong passwords
- Enable two-factor authentication (when available)
- Keep your Firebase credentials private
- Regularly update to the latest version
-
Report suspicious activity:
- If you notice unusual behavior, report it immediately
- Contact us at: mhamed.saad.ibrahim@gmail.com
- ✅ Firebase Authentication for secure user login
- ✅ Firestore Security Rules to protect data
- ✅ Environment variable protection
- ✅ Input validation on forms
- ✅ HTTPS enforcement
- ✅ Regular security audits
This project uses the following third-party services:
- Firebase (Authentication, Firestore, Hosting)
- EmailJS (Email notifications)
- Google Analytics (Usage tracking)
- reCAPTCHA (Bot protection)
- Vercel (Hosting)
Please refer to their respective security policies for more information.
This security policy is licensed under MIT License.
Last Updated: January 10, 2026