Headmon handles private health information, so please report suspected security or privacy vulnerabilities privately.
Use GitHub's private vulnerability reporting with a concise description, the affected page or version, and safe reproduction steps. Do not include a real Headmon backup, export, medical record, private photo, precise location, access token, or other personal information. Use invented data when a sample is necessary.
Please do not open a public GitHub issue for a vulnerability until the issue has been investigated and a coordinated disclosure date has been agreed. You can expect an acknowledgement within seven days. This project does not currently offer a bug bounty or authorize access to other people's data or systems.