Security

Last updated 2026-09-05.

If you have found a security problem, thank you — please report it privately using the address below rather than posting it publicly, and give it a reasonable chance to be fixed before disclosing it.

How to report

Email gaurav.gbaba@gmail.com. Include what you found, the steps to reproduce it, and what an attacker could actually do with it. A proof of concept helps enormously.

Expect an acknowledgement within a few days. This is a personal project maintained by one person in their own time, so fixes are best-effort and there is no bug bounty — that is said up front rather than after you have spent your evening on it.

In scope

Out of scope

Safe harbour

Research conducted in good faith under this policy — without degrading the service for others, without accessing or modifying data belonging to anyone else, and without publicly disclosing before a fix — is welcome, and no legal action will be pursued over it. If in doubt about whether something crosses that line, ask first.

A machine-readable version of this policy is at /.well-known/security.txt.