Skip to content

Security: karamnovr-code/mbplugin-home-assistant-guide

Security

SECURITY.md

Security policy

This repository contains no credentials or real subscriber data. Never open an issue with phone numbers, cookies, JWTs, browser profiles, SMS codes, CAPTCHA responses, MQTT passwords, Home Assistant tokens, database files, screenshots, raw carrier payloads, IP addresses or private URLs.

Report a suspected vulnerability privately through GitHub Security Advisories for this repository. For upstream MBPlugin issues, use the upstream project's reporting route.

The login window is designed for a trusted host. Keep it bound to loopback, protect any external route with HTTPS and authentication, stop it after login, and confirm the route is closed. The owner must enter SMS/CAPTCHA directly. The software must not bypass operator protections.

There aren't any published security advisories