For SkinsRestorer plugin vulnerabilities, use private vulnerability reporting. For other projects or an unavailable reporting button, email contact@skinsrestorer.net.
- Affected project, version or commit, and deployment platform.
- The impact and the permissions an attacker needs.
- A minimal reproduction with synthetic data.
- Suggested fixes or mitigations, if available.
Remove real credentials and personal data. Share proof of concept code only through the agreed private channel.
Include the exact affected version and whether the problem also occurs on current development code. Maintainers assess the report and agree on a fix and disclosure plan with the reporter. This document does not promise a response deadline or support for a specific older release.
Ordinary defects and setup questions belong in the support guide.