Skip to content

Security: FoxiFill/foxifill-extension

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not report security vulnerabilities in public issues.

Send a report to security@foxifill.com with:

  • A clear summary of the issue.
  • Steps to reproduce.
  • Affected browser and extension version.
  • Any proof of concept or screenshots that help confirm the issue.

We will acknowledge the report, validate the affected version, and coordinate a fix before public disclosure. Please allow reasonable time for investigation and remediation before sharing details publicly.

Supported versions

Version Supported
Latest Chrome Web Store release Yes
Older releases and source snapshots No

Scope

Reports are especially useful when they cover permission misuse, unintended form-data exposure, unsafe message handling, remote code execution, or a bypass of the review-before-fill workflow. General support questions and non-security bugs belong in the issue tracker.

Safe research

Use test accounts and synthetic form data. Do not access other people's data, disrupt services, or use social engineering. Good-faith research that follows this policy will be handled as coordinated security work.

Sensitive data

Do not include real credentials, tokens, private keys, personal data, or proprietary form content in issues, pull requests, screenshots, or reproduction files.

There aren't any published security advisories