Report suspected vulnerabilities with GitHub private vulnerability reporting. Do not open a public issue for an unresolved vulnerability and do not include live credentials or employee data.
The current v1.x release line receives security fixes. Operators should deploy behind HTTPS, enable secure cookies, rate-limit login and kiosk routes at the reverse proxy, restrict administrator access, back up SQLite safely, and keep the container and Python dependencies current.
PlainPunch does not claim payroll compliance or multi-tenant isolation. One deployment represents one trusted organization.