| Version | Supported |
|---|---|
| 2.x (beta) | Yes — security fixes during beta when feasible |
| 1.6.x | Yes — maintenance line until v2 stable |
| 1.5.x and older | No |
Please do not report security vulnerabilities through public GitHub issues.
Instead, report them through one of these channels:
- Email: munafaqeelmahdi@gmail.com (subject:
[Chatify Security]) - GitHub Security Advisories: Create a private advisory
Include:
- Affected Chatify version
- Laravel / PHP versions (if relevant)
- Clear description of the impact
- Steps to reproduce (privately — not in public issues)
- Proof of concept if available
Do not include live credentials, production URLs with secrets, or public zero-day exploit write-ups.
- Initial acknowledgment: within 7 days
- Triage and status update: within 14 days
- Fix timeline: depends on severity; critical issues prioritized
We will coordinate disclosure with you before publishing a fix or advisory.
Good-faith security research that follows this policy will not result in legal action from the maintainer. Do not access data that is not yours, disrupt services, or social-engineer users.