Security fixes are applied to the latest released version. Please make sure you are running the most recent release before reporting an issue.
| Version | Supported |
|---|---|
| Latest | ✅ |
| Older | ❌ |
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately using GitHub's Private Vulnerability Reporting:
- Go to the Security tab of the repository.
- Click Report a vulnerability.
- Provide a clear description, affected versions, and reproduction steps.
If you cannot use GitHub Security Advisories, contact the maintainer directly and give us a reasonable opportunity to respond before any public disclosure.
- A description of the vulnerability and its impact.
- Steps to reproduce (proof-of-concept, affected commands/flags, config).
- Affected version(s) and platform.
- Any suggested remediation, if known.
- We will acknowledge your report within 5 business days.
- We will provide an assessment and expected timeline within 10 business days.
- We will keep you informed as we work on a fix.
- We will credit you in the release notes unless you prefer to remain anonymous.
We follow a coordinated disclosure process and ask that you keep the details private until a fix has been released.
SubdomainX is a reconnaissance and attack-surface-mapping tool intended for authorized security testing only. By using this project you agree that:
- You will only scan assets you own or have explicit written permission to test.
- You are responsible for complying with all applicable laws, regulations, and the terms of service of any third-party APIs or data sources it queries.
- The maintainers accept no liability for misuse or for any damage caused by the tool. See the LICENSE for the full disclaimer of warranty.
Unauthorized scanning of systems you do not own or have permission to test may be illegal in your jurisdiction.