Only the latest stable release and the current development branch receive security fixes. Please keep your installation up to date.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, use one of these private channels:
- GitHub private vulnerability reporting (preferred): Report a vulnerability
- Email: hi@ph7.me — include "SECURITY" in the subject line.
Please include: the affected version/branch, steps to reproduce (or a proof of concept), and the impact you believe it has. You will receive an acknowledgement within a few days. Please allow a reasonable disclosure window for a fix to be released before any public disclosure — coordinated disclosure is always honored with credit in the release notes (unless you prefer to stay anonymous).
- pH7Builder is self-hosted software; server/hosting misconfiguration is out of scope, but insecure defaults shipped by pH7Builder are firmly in scope.
- Dependency vulnerabilities are monitored via
composer auditin CI; still, reports about vulnerable bundled assets (JS libraries understatic/) are very welcome.