Security

Last updated 2026-08-17 · describes the current implementation, verifiable in the source

The most sensitive thing this service can hold is a GitHub personal access token you optionally provide for faster refreshes and private-contribution counting. The design goal is simple: even a full copy of the database should not be enough to recover your token.

How stored tokens are protected

Least privilege by default

Abuse resistance

Reporting a vulnerability

Please report suspected vulnerabilities privately via GitHub security advisories for this repository, or open an issue if the report is not sensitive. The full policy lives in SECURITY.md. Only the latest deployment is supported. No bug bounty is offered, and no security certifications are claimed — the source is open for your own review.