FixMyType handles text input, so security and privacy defects deserve private reporting. Do not publish an exploit, proof of concept containing private text, or a vulnerability that could cause data loss in a public issue.
Use GitHub private vulnerability reporting. Include the affected version or commit, Windows version, clear reproduction steps, expected and actual behavior, and the smallest safe proof of concept.
If private reporting is unavailable, open a minimal public issue asking for a private contact route. Do not include exploit details.
We particularly need reports about unintended keystroke suppression, input injection, password-field handling, clipboard exposure, local-model request boundaries, Electron IPC, installer integrity, dependency compromise, and unsafe external-link handling.
The project will acknowledge a good-faith report, investigate it before public disclosure, credit reporters with permission, and publish a fix or mitigation when ready. Do not expect a bounty; this is a volunteer-funded open-source project.