Security fixes are applied to the current main branch and the latest Chrome Web Store release. Older source revisions and unpacked builds are not supported; users should update to the latest published version.
Do not open a public issue for a suspected vulnerability or include CVs, API keys, install tokens, provider responses, or other personal data in a report.
Use GitHub's Security tab → Report a vulnerability to submit a private security advisory to the maintainers. Include affected versions, impact, reproducible steps or a minimal proof of concept, and any suggested mitigation. If private vulnerability reporting is unavailable, do not publish exploit details; open a minimal issue asking the owner to enable it.
The project cannot promise a response SLA until a monitored security contact is published. Maintainers should acknowledge reports, coordinate disclosure, and publish remediation guidance before making details public.