Legal summary
Capell Security Reporting Policy
Where to report a suspected issue, what evidence helps, how to test safely, and what happens while Capell investigates package or platform risk.

| Disclosure | Covered in this document |
|---|---|
| Safe testing | Covered in this document |
| Supported scope | Covered in this document |
Sections
Plain-language summary: Email a private report with a limited reproduction and stop once the impact is clear. We will triage the risk, coordinate fixes or notices, and may restrict a package while we investigate.
Send the report privately
Send security reports to [email protected]. Include the affected package or route, the version if you know it, reproduction steps, impact, useful logs or screenshots, and whether the issue affects a live website.
Please avoid public disclosure until we have had a reasonable chance to investigate and coordinate a fix or advisory.
Issues this route is for
Useful reports include authentication bypass, account takeover, data exposure, unsafe package behaviour, malicious extensions, dependency compromise, broken authorisation, signed-route bypass, stored XSS, SQL injection, remote code execution, or marketplace install and upgrade issues that could harm a Capell site.
Test only what you are allowed to test
Do not access another person's account, download private data, alter live content, run destructive tests, degrade service, social engineer users, or test third-party systems without permission.
Use the smallest safe reproduction needed to show impact, then stop as soon as you have enough evidence.
What happens after a report
We aim to acknowledge serious reports quickly, triage impact, contact affected authors where needed, prepare fixes, and publish advisories when site owners need to act.
High-risk marketplace packages may be hidden, delisted, blocked from install, or marked unsafe while a report is investigated.
What package authors must do
Authors must keep a working security contact, respond to vulnerability reports, and publish fixes promptly. If an issue affects installed websites, Capell may notify owners or publish an advisory even when the author has not responded.