The latest tagged 2.x release is supported. Version 1.x is no longer maintained.
Use GitHub's private vulnerability reporting for this repository. If that feature is unavailable, contact the repository owner privately rather than opening a public issue with exploit details.
Include the expansion version, Folia build, PlaceholderAPI version, Java version, reproduction steps, and expected impact. You should receive an acknowledgement within seven days.
This expansion intentionally performs no telemetry, update checks, web requests, arbitrary filesystem access, or secret/environment inspection.