This project is actively maintained as part of BuildBaseKit.
Only the latest version is supported with security updates.
If you discover a security vulnerability, please report it responsibly.
Do NOT open a public issue.
Instead, contact:
Please provide:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
- Initial response: within 48 hours
- Resolution timeline depends on severity
This project involves Discord bot integration and backend services.
It follows basic practices like:
- Environment-based configuration
- Structured command and event handling
- Separation of concerns (services, handlers, config)
However, you should always:
- Never expose your Discord bot token
- Store secrets using environment variables or secret managers
- Limit Discord bot permissions (least privilege)
- Validate user inputs from commands
- Handle rate limiting and abuse protection
- Use HTTPS and secure deployment practices
- Regularly update dependencies
Be cautious about:
- Command abuse (spam, flooding)
- Unauthorized access to admin commands
- Logging sensitive user data
- Improper permission checks
This project is a boilerplate intended for learning and rapid development.
It is your responsibility to:
- Secure your bot configuration
- Implement proper authorization logic
- Adapt it for production environments
This project is part of BuildBaseKit
π https://buildbasekit.com
Security is a shared responsibility. Report issues responsibly.