PixelProof is maintained on the main branch and published through the gh-pages demo branch.
If you find a security issue, do not open a public issue with exploit details.
Please report it privately by:
- Opening a minimal, non-sensitive issue description
- Or contacting the repository maintainer directly
Primary contact: harsh@dualmindlab.tech Backup contact: harshu.dev@outlook.com
Include:
- What file or feature is affected
- Steps to reproduce the issue
- Why it matters
- Any screenshots or logs that do not expose secrets
PixelProof stores API keys locally and is designed to avoid secret exposure in the repo. If a report involves a secret, treat it as urgent and rotate it immediately.
The project is currently demo-only and is distributed as an unpacked extension rather than a public release.
- Never commit API keys, tokens, or
.envfiles - Keep generated
config.jslocal only - If a secret is exposed, rotate it immediately
- Full credentials
- Live tokens
- Private keys
- Personal data
- Complete exploit payloads that could be reused without authorization