Found a security issue in Make a Wrapped? Please report it privately so we can fix it before it becomes public.
- Report a vulnerability on GitHub (recommended). Private vulnerability reporting is enabled, so your report stays private until we publish it.
- Or email hello@devmatei.com.
Do not open a public issue, PR, or forum post about a vulnerability before we've had a chance to assess and fix it. Responsible disclosure helps everyone.
A good report is short but complete. Please share:
- The affected URL, endpoint, or component.
- A step by step way to reproduce it.
- The impact (what an attacker could gain).
- Any proof of concept, screenshots, or logs (optional).
- Your preferred way to be credited in the acknowledgements, if any.
If you found a data leak, auth bypass, injection, or anything that could put a user's data or credentials at risk, that counts. Even if you're not sure, send it our way.
Only the latest release is actively maintained for security fixes. Older versions and unreleased builds (like the experimental Navidrome Native API mode) are not guaranteed to receive patches.
| Version | Supported |
|---|---|
| Latest release | Yes |
| Older releases | No |
master / unreleased features |
No, use at your own risk |
We'll acknowledge your report as soon as we can, usually within a few days. We'll keep you updated on the fix and, once it ships, let you know on the changelog. If you want public credit, we're happy to add you to the acknowledgements.
Make a Wrapped is a small open source project. Your credentials never leave your browser when using Navidrome, and the server only stores essential data for badges and artwork. If you're unsure whether something is in scope, report it anyway.