Security
Report a vulnerability
Please email product-pass@moejay.dev with the subject “Product Pass security.” Do not open a public issue for an unpatched vulnerability.
Include affected versions, impact, reproduction steps, and a minimal proof of concept. Do not access data that is not yours or disrupt third-party services.
Architecture
- No DOTDEV-operated application backend.
- No remote code execution; extension scripts are packaged with the release.
- Optional per-site host permissions.
- Credentials are isolated from content scripts and page scripts.
- GitHub publishing requires an accepted draft and explicit confirmation.
- Screenshot and recording uploads are off by default and require per-draft opt-in plus final confirmation. Experimental uploads go directly to GitHub.
Credential limitations
Credentials persist in browser storage.local, which is not a hardware-backed secret store. Anyone with sufficient access to your browser profile or device may be able to recover them. Use narrowly scoped GitHub tokens, protect your operating-system account, and disconnect credentials on shared devices.
Supported versions
Security fixes are provided for the latest published Product Pass version. Provider APIs and experimental integrations may change independently.