The WORD DEVS team takes the security of its infrastructure and Discord bot nodes seriously.
Only the current production release receives security patches and plugin token mitigations.
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0.0 | ❌ |
If you discover a security vulnerability, token leakage vector, or denial-of-service issue:
- Do NOT open a public issue.
- Report the vulnerability privately through GitHub Private Vulnerability Reporting via the Security tab of this repository.
- Include details of the vulnerability:
- Reproduction steps or payload examples.
- Potential impact on host or Discord bot consumers.
- Proposed fixes (if available).
We will acknowledge receipt within 48 hours and work with you on patch coordination prior to public release disclosure.