Finding a security issue in a currently disabled code branch is actually nice. It means that I can post my report as a public GitHub issue instead of tracking down the right contact.

