Skip to content

Security: DeathShotXD/Comment2Shell

Security

SECURITY.md

Security policy

Scope

Comment2Shell is an offensive proof-of-concept. It is meant to be run only against systems you own or have explicit written permission to test. Reports about the tool's behaviour on unauthorized targets are out of scope.

Supported versions

Security fixes land on main. There are no long-lived release branches.

Reporting a vulnerability

If you find a bug in this tool, open a private security advisory on GitHub or contact the maintainer directly. Do not open a public issue for something that could be abused before it is fixed.

Please include:

  • a short description and the impact
  • the affected version or commit
  • reproduction steps or a proof of concept
  • any suggested fix

You should get an initial reply within a few days.

Disclosure

This project follows a coordinated disclosure model for issues in the tool itself. For issues in WordPress, report them to the WordPress security team or through their HackerOne program.

Contact

0xDeathShotX_X - github.com/DeathShotXD

There aren't any published security advisories