Skip to main content
Capell home
Live demo

Legal summary

Capell Security Reporting Policy

Where to report a suspected issue, what evidence helps, how to test safely, and what happens while Capell investigates package or platform risk.

Clear Capell operating agreements arranged with consent controls, revision layers, support correspondence, and stewardship evidence.
Key areas covered
DisclosureCovered in this document
Safe testingCovered in this document
Supported scopeCovered in this document

Plain-language summary: Email a private report with a limited reproduction and stop once the impact is clear. We will triage the risk, coordinate fixes or notices, and may restrict a package while we investigate.

Send security reports to [email protected]. Include the affected package or route, the version if you know it, reproduction steps, impact, useful logs or screenshots, and whether the issue affects a live website.

Please avoid public disclosure until we have had a reasonable chance to investigate and coordinate a fix or advisory.

Useful reports include authentication bypass, account takeover, data exposure, unsafe package behaviour, malicious extensions, dependency compromise, broken authorisation, signed-route bypass, stored XSS, SQL injection, remote code execution, or marketplace install and upgrade issues that could harm a Capell site.

Do not access another person's account, download private data, alter live content, run destructive tests, degrade service, social engineer users, or test third-party systems without permission.

Use the smallest safe reproduction needed to show impact, then stop as soon as you have enough evidence.

We aim to acknowledge serious reports quickly, triage impact, contact affected authors where needed, prepare fixes, and publish advisories when site owners need to act.

High-risk marketplace packages may be hidden, delisted, blocked from install, or marked unsafe while a report is investigated.

Authors must keep a working security contact, respond to vulnerability reports, and publish fixes promptly. If an issue affects installed websites, Capell may notify owners or publish an advisory even when the author has not responded.

Loading footer