WindowsGSH modules execute with the user's Windows permissions. WindowsGSH cannot guarantee arbitrary third-party modules, so run only code you trust.
Use the official WindowsGSH.ProjectZomboid repository or another independently verified source. Review the manifest and C# source before importing it.
Join/admin passwords, databases, player data, saves, logs, and backups may be sensitive. Restrict directory access and never post secrets or private server data.
Do not disclose an unpatched vulnerability publicly. Use GitHub private vulnerability reporting where available or contact the maintainers privately.
Include affected versions, reproduction steps, impact, and sanitized diagnostics. Remove credentials, addresses, personal paths, and server data.
Only the current module release receives security fixes unless stated otherwise.