Skip to content

Security: DragonAddons/PhDamage

Security

SECURITY.md

Security Policy

Supported Versions

Only the latest release is supported with security updates.

Version Supported
Latest Yes
Older No

Reporting a Vulnerability

If you discover a security vulnerability in PhDamage, please report it responsibly:

  1. Email: Send details to admin@xerrion.dk
  2. Do not open a public GitHub issue for security vulnerabilities
  3. Include steps to reproduce and potential impact

What to expect

  • Acknowledgment within 7 days
  • Assessment and fix timeline within 14 days
  • Credit in the changelog (unless you prefer anonymity)

Scope

In scope

  • Lua code that could expose sensitive data
  • SavedVariables handling that could be exploited
  • Any form of external communication or data leakage

Out of scope

  • World of Warcraft client vulnerabilities
  • Blizzard API behavior
  • Gameplay exploits unrelated to the addon

There aren’t any published security advisories