Only the latest version on main is actively maintained while the project is in its early stage.
Do not open a public issue for vulnerabilities, credentials, private URLs, or personal data. Use GitHub's private vulnerability reporting or a private Security Advisory after the repository is created.
Include the affected endpoint, reproduction steps, expected impact, and a minimal proof of concept with sensitive values removed. Maintainers should acknowledge a report within three working days and keep remediation details private until a fix is available.
The URL analyzer accepts only public HTTP/HTTPS pages, rejects direct private-network targets, validates redirects, and limits response size and fetch duration. Changes to these controls are high risk and require focused tests plus independent review when another maintainer is available.