Security Policy

Reporting Security Vulnerabilities

The security of this application is a priority. All security vulnerabilities must be reported privately and responsibly.

Public disclosure of security issues, including but not limited to GitHub Issues, Pull Requests, Discussions, social media, blogs, or third-party platforms, is strictly prohibited prior to coordinated disclosure.

Reporting Method

All security reports must be submitted via email:

Email: <mohsenhasannezhad@outlook.com>

Reports should include sufficient technical detail to permit verification and assessment, including:

  • A clear description of the vulnerability

  • Conditions under which the vulnerability occurs

  • Reproduction steps or proof of concept, where applicable

  • An assessment of potential impact

Incomplete, vague, or speculative reports may be disregarded.

Encrypted communication is preferred. If required, encrypted reporting options (including a PGP public key) may be provided upon request.

Scope

The following components are considered in scope for security review:

  • The official source code repository

  • The latest officially released version of the application

  • Public APIs or services directly maintained by this project

The following are out of scope:

  • Older releases

  • Forks or modified versions

  • Unofficial builds or deployments

  • Third-party integrations or environments

  • Vulnerabilities in third-party dependencies unless directly caused by this project’s implementation

  • Denial-of-service testing or resource exhaustion attacks

  • Social engineering or phishing attempts

  • Physical attacks against infrastructure

Reports outside this scope may be declined without further investigation.

Supported Versions

Only the latest officially released version of this application is supported for security updates.

There is no obligation to investigate or remediate vulnerabilities affecting unsupported versions or external modifications.

Response Policy

Security reports are reviewed on a best-effort basis.

While no guarantees are made regarding response or remediation timelines, the project aims to:

  • Acknowledge receipt of a valid security report within 7 days

  • Provide an initial assessment within 30 days, where feasible

  • Coordinate disclosure after a reasonable remediation window

Complex vulnerabilities may require additional investigation time.

The developer retains sole discretion to determine whether a reported issue constitutes a security vulnerability and whether remediation is warranted.

Coordinated Disclosure Policy

This project follows a coordinated disclosure model.

By submitting a security report, the reporter agrees to:

  • Allow reasonable time for investigation and mitigation

  • Refrain from public disclosure without explicit written consent

  • Avoid exploiting the vulnerability beyond what is strictly necessary to demonstrate its existence

Failure to adhere to these expectations may fall outside the protections described in this policy.

Safe Harbor

Security researchers acting in good faith, in compliance with this policy, and without intent to cause harm, service disruption, or data compromise, will not be subject to legal action by the project for their research.

Good-faith research includes:

  • Responsible testing within defined scope

  • Avoiding privacy violations

  • Avoiding destruction or alteration of data

  • Reporting findings promptly and privately

Activities that exceed these boundaries may not qualify for safe harbor.

CVE Policy

For confirmed security vulnerabilities, this project may:

  • Request a CVE identifier from an appropriate numbering authority

  • Publish a security advisory

  • Coordinate disclosure in accordance with industry best practices

The decision to request or assign a CVE identifier remains at the discretion of the project maintainer.

Scope, Use Restrictions, and Intent

This application is intended exclusively for lawful, ethical, and authorized use.

The developer explicitly disclaims any intent, encouragement, or authorization for the use of this application in activities including, but not limited to:

  • Unauthorized access to systems, services, or data

  • Surveillance, profiling, or tracking of individuals without consent

  • Collection, exposure, or exploitation of personal or sensitive information

  • Any activity that violates privacy rights, local laws, or international regulations

Any use of this application for malicious, abusive, unethical, or illegal purposes falls entirely outside the intended scope of the project and is undertaken solely at the user’s own risk and responsibility.

The developer bears no responsibility or liability for damages, losses, or legal consequences arising from misuse, abuse, or unlawful deployment of this application.

Reports that focus on misuse scenarios rather than demonstrable security flaws in the application itself may be declined.

Acknowledgement of Good-Faith Research

Security researchers who act in good faith and adhere to this policy are acknowledged and appreciated. Recognition of such contributions does not imply acceptance of liability, obligation, or endorsement.

No Warranty

This application is provided “as is”, without warranty of any kind, express or implied, including but not limited to warranties of security, fitness for a particular purpose, or non-infringement.

The existence of this security policy does not imply any guarantee that vulnerabilities will be discovered, reported, or resolved.