Do not open a public issue for a vulnerability that could put visitors or contributors at risk. Contact the repository owner privately through their GitHub profile with:
- the affected file or behavior;
- reproduction steps;
- likely impact;
- any suggested mitigation.
The maintainer will acknowledge the report, assess severity, and coordinate disclosure. This static project currently has no supported release branches; fixes are applied to main and deployed through the configured site hosting.
Relevant reports include script injection, unsafe community-content parsing, compromised dependencies, leaked credentials, and privacy-impacting analytics behavior.