Report a Plugin Security Issue

Tell us about a serious unresolved security issue or malware in a third-party plugin.

Third-party plugins (those outside the filament/ namespace) are built and maintained by the community. Filament does not review, endorse, or vet the security of these plugins. However, we want to keep the ecosystem safe, so we'd like to hear about plugins with serious unresolved problems.

Please use this form only to report a third-party plugin that has:

  • an unresolved security vulnerability, or
  • malware or otherwise malicious code,

and whose author has not responded to your attempts to report the issue to them privately.

If you have found a bug or a non-security issue, please contact the plugin's author directly instead. For security issues, always try to report the problem to the author privately first and give them a reasonable chance to respond before submitting this form.

If a plugin's directory listing is inaccurate or you need to report another non-security listing issue, email [email protected] for help. Do not use that address to report plugin bugs or implementation issues; send those to the plugin's author instead.

Submit a report

Provide as much detail as you can. We review every report and will take action where appropriate.

Include affected versions, reproduction steps, impact, and links to any private report where possible.

Use a private security channel where one is available, and include dates and any response you received.

Fields marked with an asterisk are required.