| Version | Supported |
|---|---|
| 0.x | ✅ |
| < 0.1 | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report vulnerabilities through GitHub private vulnerability reporting for this repository.
If private vulnerability reporting is unavailable or unusable for your report, email the maintainers at marioaldayuz315@gmail.com.
When reporting a vulnerability, please include:
- The affected version, tag, or commit SHA
- A description of the issue and why you believe it is security-sensitive
- Steps to reproduce, or a proof of concept
- Any relevant logs, payloads, or screenshots
- The potential impact
- Any suggested mitigations or fixes, if known
You can expect an acknowledgment within 3 business days.
After acknowledgment, we will assess the report and follow up with next steps. If the issue is confirmed, we will work on a fix and coordinate disclosure timing with the reporter when appropriate.
If a report is validated, we may publish a GitHub Security Advisory once remediation details are ready to share publicly.
In scope: the browser-extension code in this repository.
Out of scope: HighLevel's own platform (report platform issues to HighLevel), and the contents of any sub-account you do not own or operate. Note that these tools intentionally never handle credentials — a report that a session token was mishandled would be treated as high severity precisely because the design promise is that it never happens.