This project is an experimental local-development tool, not a hardened
multi-tenant service. The latest main branch receives security fixes.
Use GitHub's private vulnerability reporting/security-advisory feature for this repository. Do not include credentials, merchant feeds, customer data, or other sensitive material in a public issue.
If a report involves a credential, revoke or rotate the credential first. File removal and Git history rewriting are not substitutes for rotation.
Before exposing the service to untrusted users, add authentication, tenant isolation, secret management, URL egress controls, request/response size limits, rate limiting, and a documented data-retention policy.