| Version | Supported |
|---|---|
| 1.x | ✅ |
If you discover a security vulnerability in Motionly, please report it by:
- DO NOT open a public issue
- Email the maintainers with details
- Include steps to reproduce if possible
- Allow time for a fix before public disclosure
We take security seriously and will respond promptly to legitimate reports.
When using Motionly:
- Only load
.motionfiles from trusted sources - Validate user-provided content before parsing
- Be cautious with assets from untrusted sources
- Keep dependencies up to date
- The
.motionparser does not execute arbitrary code - Asset loading is restricted to images and SVGs
- Export functionality runs in browser sandbox