We take the security of our software seriously. If you believe you have discovered a security vulnerability in this MODX Extra, please follow the responsible disclosure procedure described below.
The following versions are currently being supported with security updates.
| Version | Supported |
|---|---|
| 2.x | Yes |
| 1.x | Critical vulnerabilities only |
Do not open a public GitHub issue for security vulnerabilities. Public disclosure before a patch is available puts all users of this MODX Extra at risk.
To report a vulnerability, use one of the following channels:
- You can open a private security report in this repository.
- You can send an email to office@treehillstudio.com
We aim to respond to all reports within 24–48 hours of receipt.