Please report vulnerabilities privately via GitHub's "Report a vulnerability" form rather than opening a public issue.
- These tools talk to Nixplay's unofficial web API with credentials the
user supplies via
.envor environment variables. Credentials are only ever sent toapi.nixplay.comand are never written to disk by the tools. nixplay-prune --executepermanently deletes photos from the authenticated Nixplay account; its backup interlock and verification behavior are security-relevant and regressions there are treated as vulnerabilities.