We actively investigate security vulnerabilities in Magento versions that are currently supported by Magento.
If your Magento version is no longer officially supported by Magento, we may not be able to provide a security fix. We strongly recommend keeping your Magento installation up to date and applying the latest available security patches.
If you believe you have discovered a security vulnerability in this project, please report it privately.
The preferred way to report a vulnerability is through GitHub's private vulnerability reporting for this repository. This allows you to provide vulnerability details directly and securely to the maintainers.
You can also report a vulnerability by email at support@buckaroo.nl if private vulnerability reporting is not suitable for your situation.
Please do not report security vulnerabilities through public GitHub issues, pull requests, or other public channels.
When reporting a vulnerability, please provide as much relevant information as possible, including:
- A description of the vulnerability and its potential impact
- The affected Magento and module versions
- Steps to reproduce the vulnerability
- Any proof-of-concept or other relevant technical details
Security reports receive our highest priority.
We aim to acknowledge security reports within 48 hours and will provide further updates as our investigation progresses.
We appreciate responsible disclosure and thank you for helping us keep this project secure.