What is the preferred method for reporting security vulnerabilties / patches (I'd prefer to not post to the public forum before a fix is available). Is this project maintained? Have not been able to reach maintainers via the email on the homepage.