Skip to content

Security: Carlymaxx/maxxtechxmd

Security

SECURITY.md

Security Policy — MAXX-XMD ⚡

Supported Versions

Version Supported
v3.2.x ✅ Active support
v3.1.x ⚠️ Critical fixes only
< v3.0 ❌ No longer supported

Reporting a Vulnerability

Do NOT open a public GitHub issue for security vulnerabilities.

Instead, report privately:

  1. Email: security@maxxtech.co.ke
  2. WhatsApp: Contact via Channel

What to Include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your suggested fix (if any)

Response Timeline

  • Acknowledgement: Within 48 hours
  • Assessment: Within 7 days
  • Fix release: Within 14 days (critical), 30 days (moderate)

Security Best Practices for Users

  • ✅ Never share your SESSION_ID publicly — it grants full WhatsApp access
  • ✅ Rotate your Session ID regularly via pair.maxxtech.co.ke
  • ✅ Keep HEROKU_API_KEY and PAYSTACK_SECRET_KEY private
  • ✅ Use WORK_MODE=private if you don't want the bot to respond to strangers

MAXX-XMD v3.2.0 — Built by Carlymaxx

There aren't any published security advisories