Minn Admin is an admin surface: it manages content, users, plugins and settings on real sites, so security reports get priority over everything else.
Email security@minnadmin.com. You can expect an acknowledgment within 48 hours and a fix or a concrete timeline within a week for anything exploitable. Credit is yours unless you ask otherwise; coordinated disclosure timing is negotiable and reasonable.
Please include the Minn Admin version, the role of the user in your reproduction (admin-only issues are still issues, but capability context changes severity), and steps or a request trace.
The latest release. Minn ships small releases frequently and the built-in updater verifies each download against a published sha256, so staying current is cheap; fixes are not backported.
The minn-admin plugin: its REST routes, the admin app, bundled adapters
and the self-updater. Out of scope: the minnadmin.com website, third-party
plugins that integrate with Minn (report those to their authors; if Minn's
handling of their data is the problem, that part is in scope), and issues
requiring an already-compromised administrator account.
A few properties worth knowing before auditing (details in docs/goals.md and the code):
- The app gate requires a logged-in user with
edit_posts; every REST route carries its own server-sidepermission_callbackon top of that. - Third-party plugins integrate as data descriptors only. Their PHP never runs in Minn's render paths and their HTML/CSS/JS never reaches the app; values are escaped at the render edge.
- When a shim must read third-party serialized storage, it uses a bounded parser or constrained decoding, validates the resulting shape, and does not instantiate arbitrary classes. An exact vendor class allowlist is used only where the vendor API requires its own value objects. Shim SQL is prefix-scoped and prepared.
- Updates install only after the downloaded zip's sha256 matches the value published in the release manifest.
- A browser test suite (286 suites at the time of writing) includes an enforced zero-external-requests invariant for the app chrome.