Only the latest minor release receives security fixes while the project is below 1.0.
Please do not open a public issue. Report it privately through GitHub's "Report a vulnerability" button (Security tab of the repository). Include a description, affected versions and, if possible, a minimal reproduction. You will get an answer within a few days.
This library turns client-controlled request parameters into SQL. Reports about SQL injection, filter/field-name whitelist bypasses, or ways to read data outside the configured query/scope are especially welcome.