Before the first public release, security fixes are made on the main branch. After publication, only the latest released Basicrum plugin version will receive security fixes unless a release notice states otherwise.
Do not report a suspected vulnerability in a public GitHub issue. Contact the maintainer privately through the Basicrum contact form and identify the report as a security issue.
Include, where possible:
- the affected plugin version and WordPress/PHP versions;
- the vulnerable component and required configuration;
- reproducible steps or a minimal proof of concept;
- the expected and observed security impact; and
- any suggested remediation or disclosure constraints.
Avoid accessing data that does not belong to you, degrading a live service, or testing against production systems without permission. Please allow time for the report to be reproduced and addressed before public disclosure.
General support questions and non-sensitive defects may use the repository's public issue tracker.