This project is currently maintained on the main branch only.
| Version | Supported |
|---|---|
main |
Yes |
| older snapshots | No |
Do not open a public GitHub issue for suspected vulnerabilities.
Report security issues privately to the maintainer before public disclosure. Include:
- A clear description of the issue
- Reproduction steps or a proof of concept
- Impact assessment
- Any suggested remediation
If the issue involves exposed credentials or third-party account access, rotate affected credentials immediately and note that in the report.
- I will acknowledge receipt as soon as practical.
- I will validate the report and determine severity.
- If the report is valid, I will prepare and ship a fix before public disclosure where possible.
- Once a fix is available, I may publish a changelog entry or advisory describing the issue at a high level.
This repository contains a browser app and Netlify serverless functions. Reports are especially helpful for:
- Authentication and session handling flaws
- CSRF, XSS, injection, SSRF, and data exposure issues
- Dependency and supply-chain risks
- Privacy or unsafe default configuration problems