The current 0.2 series is maintained. For a vulnerability, use GitHub private vulnerability reporting if available, or open an issue requesting a private contact without posting an exploit, secrets or sensitive images. Do not include private images in reports.
Include the version, operating system, file type and a minimal non-sensitive reproduction. This is a small project; no response-time SLA is promised.
Inputs are size bounded and decoded locally. The independent verifier runs a subprocess with minimal state; it is not a security sandbox. Exported HTML includes the decoder and recipe and does not need a server. Binaries are currently unsigned. Verify published SHA-256 sums; Windows may show an unfamiliar-publisher prompt.