Security fixes are provided on a best-effort basis for:
| Version | Supported |
|---|---|
Latest release on main |
Yes |
Current dev branch |
Yes |
| Older releases | No |
Report vulnerabilities through GitHub private vulnerability reporting.
Do not open a public issue containing exploit details, Plex tokens, cookies, room credentials, private server addresses, or personal data. Include the affected version or commit, reproduction steps, impact, and a minimal redacted configuration when relevant.
Non-sensitive hardening ideas can use a normal issue after any disclosure risk has passed.