Since this project is in an early stage and didn't reach a maturity to actually support semantic versioning, any secruity relevant fix will be available in the most recent version only.
Please report (suspected) security vulnerabilities to [email protected]. You will receive a response from me within 48 hours. If the issue is confirmed, we will release a patch as soon as possible depending on complexity, but should be within a few days.