Skip to main content
Flex Forms support — Help Center paths, contact options, and issue templates

Report a bug

Something broken? File it on the public Issues board with steps to reproduce.

Request a feature

Missing something? Tell us what you’re trying to build.

License portal

Manage your license key, domains, and plan.

What's new

Recent product updates and Help Center highlights.

Report a security issue

Suspected vulnerability? Use private disclosure — never a public GitHub issue.
1

Search the docs first

Most installation, config, and “how do I…” questions are answered in Get started, Guides, and Developers.
2

Check What's new

If something changed recently, check What’s new before filing a bug.
3

File a focused bug report

Include your Flex Forms version, Filament/Laravel/PHP versions, and exact reproduction steps — screenshots or a short screen recording help a lot for UI issues.
4

Flag license/billing issues separately

License key, domain activation, or billing questions go through the license portal, not GitHub Issues.

Report a security vulnerability

If you believe you found a flaw that could let someone bypass authentication, read another tenant’s submissions, execute code, or exfiltrate data without going through the product’s documented controls, treat it as a security report — not a regular bug.
Do not open a public GitHub issue, post on social media, or share exploit details in community threads before we have had a chance to respond. Public disclosure makes incidents harder to fix and puts other customers at risk.

What belongs in a security report

Report issues in Flex Forms package code when they affect confidentiality, integrity, or availability — for example:
  • Authentication or authorization bypass in Studio, fill, embed, or Insights share surfaces
  • Cross-tenant or cross-form data leakage in submissions, Contacts, or exports
  • Server-side request forgery (SSRF) or unsafe outbound HTTP beyond the documented integration hardening
  • Stored or reflected XSS delivered through fill output, embed parents, or shared Insights pages
  • Bypass of answer encryption, access gates, or CAPTCHA when the bypass is in product code — not misconfiguration
  • Privilege escalation around Studio permissions or Filament policy hooks shipped with the package
Not sure? Email anyway with a short impact summary. We would rather triage a borderline report privately than miss a real issue.

What is not a security report

Use the public bug template instead for:
  • Visual glitches, copy issues, or Studio UX bugs without a security impact
  • License portal, billing, or domain activation problems → License Portal
  • Integration failures caused by wrong API keys, field maps, or provider rate limits
  • Hardening advice for your Laravel app (WAF, CSP, server headers) unless Flex Forms ships insecure defaults you can demonstrate

How to send a private report

1

Email us privately

Send details to [email protected] with the subject line Flex Forms security (or prefix your own subject with that phrase so it is routed correctly).Enterprise customers may also reach the priority channel agreed in your plan (email or private Slack) — still mark the message as a security report.
2

Include enough context to reproduce

Help us move fast:
  • Flex Forms version (composer show janczakb/filament-flex-forms)
  • Laravel, PHP, Filament, Livewire versions
  • Hostname / environment (production, staging, local — no need for secrets)
  • Impact — who can exploit it, what data or actions are exposed
  • Steps to reproduce — minimal, ordered list
  • Proof of concept — curl, screenshots, or a short video if UI-related
  • Your contact — email (and optional PGP fingerprint if you encrypt mail)
3

Wait for acknowledgment before public disclosure

We coordinate fix timing with you. Please do not publish write-ups, scanner signatures, or exploit code until we confirm a release or agreed disclosure date.

What happens after you report

Supported versions

Security fixes are published for currently supported Flex Forms releases. Check SECURITY.md on GitHub for the supported version table. If you are on an older major, upgrade via Upgrading before expecting a backport.
Scope reminder: Flex Forms runs in your Laravel app. Server misconfiguration (debug mode on production, open S3 buckets, missing HTTPS) is outside package scope — but tell us if you think the product encourages an unsafe default we should change.

Bug reports and feature requests are triaged on the public Issues board; response time depends on severity and current volume.
Use Report a security vulnerability above — private email to [email protected], never a public GitHub issue. Full policy: SECURITY.md.
Enterprise ($799 / year) includes Priority support by email or a private Slack channel, Prioritized feature requests, and Help shape the roadmap. See Standard, Pro, Enterprise or reach out via the license portal.
Yearly: Standard 99Pro99** · Pro **199 · Enterprise 799.Lifetime799**. Lifetime **899 one-time (Pro features · 10 activations · updates forever). Full comparison: Plans & Pricing.
Last modified on September 7, 2026