Please do not disclose suspected vulnerabilities in public issues, pull requests, discussions, or social media.
Send a private report to security@phpaisdk.com. Include a clear description, affected package and version, reproduction steps, impact, and any suggested remediation.
We will acknowledge receipt, investigate the report, and coordinate a responsible fix and disclosure. Please allow time for a response before discussing the issue publicly.
Security fixes are provided for the latest stable release line of an affected package. If a report affects an older release line, include the exact version so we can assess whether a backport is appropriate.