This script runs on other people's websites, so we take reports seriously.
Please do not open a public issue. Report it privately through GitHub instead:
- Open the Security tab of this repository.
- Choose Report a vulnerability.
Include what an attacker could do, the steps to reproduce it, and the browser you used. We will acknowledge the report, keep you updated while we work on a fix, and credit you in the release notes unless you would rather stay anonymous.
- Anything that lets a data attribute, stored preference or host page inject script or arbitrary CSS through the widget.
- Anything that makes the widget leak data off the visitor's device. It should never make a network request.
- Anything that lets the widget break or hide the host page in a way the visitor cannot undo with the reset button.
Security fixes go into the latest release of the current major version.