Please do not report security vulnerabilities in public issues.
Send a report to security@foxifill.com with:
- A clear summary of the issue.
- Steps to reproduce.
- Affected browser and extension version.
- Any proof of concept or screenshots that help confirm the issue.
We will acknowledge the report, validate the affected version, and coordinate a fix before public disclosure. Please allow reasonable time for investigation and remediation before sharing details publicly.
| Version | Supported |
|---|---|
| Latest Chrome Web Store release | Yes |
| Older releases and source snapshots | No |
Reports are especially useful when they cover permission misuse, unintended form-data exposure, unsafe message handling, remote code execution, or a bypass of the review-before-fill workflow. General support questions and non-security bugs belong in the issue tracker.
Use test accounts and synthetic form data. Do not access other people's data, disrupt services, or use social engineering. Good-faith research that follows this policy will be handled as coordinated security work.
Do not include real credentials, tokens, private keys, personal data, or proprietary form content in issues, pull requests, screenshots, or reproduction files.