| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
We take the security of phpMyFAQ and its ecosystem seriously. If you believe you have found a vulnerability, please report it privately so we can triage and fix it promptly.
This document is the single point of contact for vulnerability reports concerning phpMyFAQ and serves as our coordinated vulnerability disclosure (CVD) policy. Our internal handling procedure is documented in docs/security-process.md.
The following branches are supported for security fixes:
| Version | Status | Minimum PHP | Supported until |
|---|---|---|---|
| 4.2.x | Active support | 8.4 | Until 4.3.0 + 6 months |
| 4.1.x | Security fixes only | 8.3 | 2027-06-30 |
| < 4.1 | End of life (EOL) | 8.2 | Unsupported |
We may backport critical fixes at our discretion. Users should keep up to date with the latest minor/patch releases. Running an EOL version is not a supported configuration; reports affecting only EOL versions will be closed with an upgrade recommendation.
Please use one of the following private channels:
Reports are accepted in English and German.
When reporting, please include where possible:
Please do not open a public issue, pull request, or discussion for security reports.
We aim to meet the following response targets:
| Stage | Target |
|---|---|
| Acknowledgement of report | 2 business days |
| Initial triage and severity assessment | 7 calendar days |
| Fix — Critical | 7–14 days |
| Fix — High | 30 days |
| Fix — Medium | 60 days |
| Fix — Low | 90 days |
Severity is assessed using CVSS v3.1 (and v4.0 where applicable). These are targets, not contractual guarantees; phpMyFAQ is provided without warranty under the terms of its licence. Organisations that require contractual response times can obtain professional support directly from the maintainer — see https://www.phpmyfaq.de/support. There are no third-party support vendors endorsed by the project.
We provide periodic updates while triage and remediation are in progress.
We do not operate a bug bounty programme and do not offer monetary rewards.
In scope:
Out of scope (non-exhaustive):
Security also depends on how phpMyFAQ is operated. See the hardening notes in docs/deployment.md and docs/installation.md for recommended file permissions, TLS configuration, and settings that should be changed from their defaults before going into production.
We will not pursue legal action against researchers who:
This safe harbor covers the phpMyFAQ project. It does not bind third parties whose systems happen to run phpMyFAQ — do not test against installations you do not own or have written permission to test.
phpMyFAQ is free and open source software, licensed under the Mozilla Public License 2.0. The software itself is made available to everyone free of charge; development is funded by voluntary donations and sponsorship. Security fixes and advisories are published for all users at no cost, ship in public releases, and are never conditional on paid services.
Optional professional services (custom development, consulting, installation, training, and prioritised handling of issues) are offered separately by the maintainer — see https://www.phpmyfaq.de/support. These services do not change how vulnerabilities are triaged, fixed, or disclosed under this policy.
This policy, together with the process documented in docs/security-process.md, describes our coordinated vulnerability disclosure process and single reporting point.
Organisations subject to their own regulatory requirements (for example the EU Cyber Resilience Act, NIS2, or ISO 27001) that need documented assurances beyond this policy should contact security@phpmyfaq.de to discuss what we can provide.
If you have any questions about this policy, contact us at security@phpmyfaq.de.
Thank you for helping keep phpMyFAQ and its users safe.
Copyright © 2001–2026 Thorsten Rinne and the phpMyFAQ Team
| Back | FazBrowse Home | New Git URL |