Skip to content

Security: idevtim/demarkup

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
Latest release Yes
Older versions No

Reporting a Vulnerability

Please do not open a public issue for security vulnerabilities.

Instead, email security@idevtim.com with:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact

Response Timeline

  • Initial response: within 48 hours
  • Fix timeline: depends on severity, but we aim for a patch within 7 days for critical issues

Scope

Security concerns relevant to DeMarkup include:

  • Content script injection or XSS via converted page content
  • Clipboard data leakage
  • Unexpected permission escalation
  • Data exfiltration through the extension

Thank you for helping keep DeMarkup safe.

There aren't any published security advisories