| Version | Supported |
|---|---|
| 2.0.x | ✅ |
| < 2.0 | ❌ |
If you discover a security vulnerability in PhishWatch, please report it responsibly:
- Do NOT open a public GitHub issue
- Email: ali@alenezi.me with subject
[PhishWatch Security] - Include: description, reproduction steps, potential impact
- You will receive acknowledgment within 48 hours
- Always change
SECRET_KEYin production - Run behind a reverse proxy (nginx/Caddy) with TLS
- Use Docker for isolated deployment
- Restrict network access to the dashboard
- Regularly update dependencies