Please do not report security issues via public GitHub issues — use GitHub's "Report a vulnerability" (repository Security tab → Advisories) instead. You will get a response within a few days.
Deutsch: Bitte melde Sicherheitsprobleme nicht über öffentliche GitHub-Issues, sondern vertraulich über GitHubs „Report a vulnerability" (Tab Security → Advisories in diesem Repository).
PlugNap deliberately has no internet permission, no trackers and no network functionality. The relevant attack surface is therefore primarily the exported components (launcher activity, boot receiver, quick-settings tile) and the handling of the Do Not Disturb permission.