InstaReport takes security seriously. This policy explains how to report vulnerabilities and how we handle them.
Only the latest release receives security fixes. Please always update to the newest version from the official releases.
| Version | Supported |
|---|---|
| Latest release | β |
| Older releases | β |
Please do not open a public issue for security vulnerabilities. Instead, report them privately:
- Email / Contact: reach the team via the official Telegram channel: https://t.me/iescly
- Preferred: private message on Telegram with the subject
[SECURITY]
When reporting, please include:
- The affected version.
- A clear description of the vulnerability.
- Steps to reproduce (if applicable).
- Impact assessment (what an attacker could do).
- Your contact details.
- Acknowledgment: you will receive an acknowledgment within 72 hours of your report.
- Assessment: we will investigate and confirm whether the issue is valid.
- Fix: valid issues are addressed in the next release as quickly as possible.
- Disclosure: we coordinate disclosure with the reporter. We generally recommend reporting through a private channel so details are not publicized before a fix is available.
- Only download InstaReport from the official resources:
- Website: https://instagramban.lovable.app
- GitHub: https://github.com/iEsclyDev/instareport
- Telegram: https://t.me/iescly
- Beware of fake copies and impersonators. Always verify the channel before downloading software or purchasing licenses.
- Never share your license key or hardware-ID information publicly.
- Keep your software updated to the latest version.