Until the first stable release, security fixes are applied to the latest version on the default branch.
Do not report vulnerabilities in a public issue.
Use the repository's Security tab and choose Report a vulnerability. If private vulnerability reporting is not available, use the private maintainer contact shown in the Chrome Web Store publisher profile.
Include:
- The affected version and browser version.
- Reproduction steps or a minimal proof of concept.
- The expected and observed impact.
- Whether page content, profile data, API keys, or permissions are involved.
Do not include real credentials or personal data. The maintainer will acknowledge a complete report as soon as practical, coordinate a fix, and credit the reporter unless anonymity is requested.