GoodWebTools runs entirely in the browser — files never leave your device — so the attack surface is small, but we take reports seriously.
Please do not open a public issue for security problems. Instead, use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Click Report a vulnerability.
- Describe the issue and reproduction steps.
We aim to acknowledge reports within a few days. Once a fix ships, we're happy to credit you (unless you prefer to remain anonymous).
The latest deployed version (main) is supported. There are no long-term
support branches.