Security fixes are applied to the latest released version of the extension. We recommend always running the most recent build from the Chrome Web Store.
| Version | Supported |
|---|---|
| 1.2.x | ✅ |
| < 1.2 | ❌ |
Please do not open a public GitHub issue for security-sensitive reports.
Instead, report vulnerabilities privately using one of the following channels:
- GitHub Security Advisories — use the private vulnerability reporting form (preferred).
- Email — send details to dr.zhihua.lai@gmail.com, or use the contact form on justyy.com.
When reporting, please include:
- A clear description of the issue and its potential impact.
- Step-by-step instructions to reproduce it.
- The extension version, Chrome version, and operating system.
- Any relevant logs, screenshots, or proof-of-concept code.
- We aim to acknowledge new reports within 5 business days.
- We will investigate, keep you informed of progress, and coordinate a fix and disclosure timeline with you.
- Once a fix is released, we are happy to credit reporters who wish to be acknowledged.
This extension runs entirely in the browser, requests only the storage
permission, and does not transmit user data. Reports about data handling,
content-script injection, permission scope, or supply-chain concerns
(dependencies, build tooling) are all in scope.
Thank you for helping keep users safe.