Important: If you have discovered a security vulnerability, please do not open a public GitHub issue. Instead, follow the responsible disclosure process described below.

Our Commitment

We take the security of OpenDroid and our users seriously. As an open-source project that interacts with sensitive device permissions (Accessibility Service, phone, SMS, system settings), we recognize the importance of promptly addressing security concerns.

Supported Versions

Only the latest release version of OpenDroid is actively supported with security updates.

Version Status
≥ 1.0 (Latest Release) ✓ Supported
< 1.0 (Pre-release) ✗ Not Supported

Reporting a Vulnerability

If you believe you have found a security vulnerability in OpenDroid, please report it responsibly:

Step 1: Contact Us Privately

Send a detailed report to opendroid.ai@gmail.com or yashabalam707@gmail.com with:

Step 2: Our Response

After receiving your report:

Step 3: Disclosure

Once the vulnerability is patched:

Security Best Practices for Users

To ensure the security of your OpenDroid installation:

Scope

The following areas are in scope for security reports:

Out of Scope

Acknowledgements

We gratefully acknowledge the security researchers who help keep OpenDroid secure. Contributors who responsibly disclose vulnerabilities will be recognized in our security advisories and (optionally) in this section.