Skip to content

Security: munafio/chatify

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
2.x (beta) Yes — security fixes during beta when feasible
1.6.x Yes — maintenance line until v2 stable
1.5.x and older No

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, report them through one of these channels:

  1. Email: munafaqeelmahdi@gmail.com (subject: [Chatify Security])
  2. GitHub Security Advisories: Create a private advisory

Include:

  • Affected Chatify version
  • Laravel / PHP versions (if relevant)
  • Clear description of the impact
  • Steps to reproduce (privately — not in public issues)
  • Proof of concept if available

Do not include live credentials, production URLs with secrets, or public zero-day exploit write-ups.

Response Timeline

  • Initial acknowledgment: within 7 days
  • Triage and status update: within 14 days
  • Fix timeline: depends on severity; critical issues prioritized

We will coordinate disclosure with you before publishing a fix or advisory.

Safe Harbor

Good-faith security research that follows this policy will not result in legal action from the maintainer. Do not access data that is not yours, disrupt services, or social-engineer users.

There aren't any published security advisories