Security fixes are maintained on the latest 0.1.x release. The calculator is
a client-only application: it does not store credentials, transmit user input,
or provide a server-side API.
Use GitHub's Security tab and choose Report a vulnerability. Include the affected browser, the input sequence, the observed impact, and a minimal reproduction. Do not publish an unpatched vulnerability in an issue.
Reports are acknowledged within five business days. Valid issues are fixed on a private branch, covered by a regression test, and disclosed with the release that contains the fix.