Security fixes are currently focused on the latest release on the main branch.
| Version | Supported |
|---|---|
| 2.x | Yes |
| < 2.0 | No |
Please do not disclose suspected vulnerabilities in a public GitHub issue.
Until a dedicated private security advisory channel is configured, contact the repository maintainer privately through the GitHub profile associated with this repository and include:
- A clear description of the vulnerability.
- The affected component and version/commit.
- Reproduction steps or a minimal proof of concept.
- Security impact.
- Any suggested mitigation.
Do not include real credentials, session cookies, API keys, or private user data in reports.
Only scan systems you own or have explicit permission to assess. API Scanner Pro is a security testing utility; users are responsible for authorization and compliance with applicable laws and service terms.
The scanner uses deterministic heuristics and should not be treated as a definitive malware, phishing, or vulnerability verdict.
Reports will be reviewed by the maintainer. Valid findings will be triaged, reproduced where practical, fixed or mitigated, and documented in an appropriate release note.