Skip to content

Security: devashishPM/GridPluck

Security

SECURITY.md

Security policy

Reporting a vulnerability

Please do not publish sensitive vulnerability details in a public issue. Report them through GitHub private vulnerability reporting.

Include the affected version, a minimal reproduction, potential impact, and any suggested mitigation. You should receive an acknowledgement within seven days.

Security model

GridPluck has no backend, account system, analytics, or network API. It runs only after the user clicks the extension icon and reads only the currently loaded document structure. Spreadsheet exports neutralize values beginning with formula-control characters to reduce CSV injection risk.

There aren't any published security advisories