Please do not publish suspected vulnerabilities in a public issue.
If you identify a security problem, contact the repository owner privately through the contact method listed on the GitHub profile. Do not include real customer data, credentials, access tokens, database backups, or other secrets in reports.
Never commit .env files, database backups, production credentials, or client
data to this repository.