The latest published 1.3.x release is supported.
Please do not open a public issue for security problems. Instead, report them privately via GitHub Security Advisories (https://github.com/saifmohamedsv/hookli/security/advisories/new) or by email to saifmohamed.dev@gmail.com.
You'll get an acknowledgement within a few days, and a fix or mitigation as soon as practical. hookli has zero runtime dependencies, so the attack surface is small.