| Version | Supported |
|---|---|
| 1.x | ✅ |
If you discover a security vulnerability in the Massachusetts Writers Directory, please report it responsibly:
- Do not open a public GitHub issue for security vulnerabilities
- Email the project maintainers with a detailed description of the vulnerability
- Include steps to reproduce the issue if possible
- Allow reasonable time for a fix before public disclosure
- Author profile information is publicly visible by design
- Application submissions are stored in Flex Objects YAML files
- Email addresses in applications should be handled according to privacy requirements
- Profile images are validated for file type
- Images are stored in designated directories within the Grav installation
- Uploaded files should be scanned by server-side security measures
- Admin panel access is controlled by Grav's Login plugin
- Use strong passwords and consider two-factor authentication
- Limit admin access to trusted users only
- Keep Grav CMS updated to the latest stable version
- Regularly update plugins via GPM
- Monitor Grav security advisories at https://github.com/getgrav/grav/security
This project may integrate with:
- Mapbox: For interactive maps (requires API token)
- Email services: For application notifications
Ensure proper API key management and follow each service's security best practices.