Skip to content

Security: HostX0/menu-cross

SECURITY.md

Security policy

Please report suspected security vulnerabilities privately through this repository's GitHub Security → Report a vulnerability page. Do not post credentials, session cookies or exploitation instructions in a public issue.

Include the affected route/module, reproducible steps, expected impact and a minimal safe example. Test only systems you own or are authorized to test. The currently maintained branch is main; no response-time guarantee is offered.

The app's network boundary is intentionally restricted to public Baly/Talabat menu and image hosts. Authentication bypasses, CAPTCHA circumvention and arbitrary URL proxying are out of scope. Operators should apply hosting-level rate limits and resource budgets appropriate to their audience.

There aren't any published security advisories