Website safeguards
The public account scaffold hashes passwords, uses prepared database queries, validates CSRF tokens on browser forms and regenerates the session on login. Session cookies use HttpOnly and SameSite=Lax, with Secure enabled over HTTPS. Google login validates OAuth state. PayPal webhooks are signature-checked before subscription updates.
Shared responsibility
Use strong, unique credentials and multi-factor authentication on the social and developer accounts you connect. Grant only necessary API permissions, remove unused connections and rotate a credential if you believe it was exposed. Never send an API secret in a contact message or place it in a public URL.
Report a vulnerability privately
Contact support with the subject “Security report”. Include the affected URL, a safe reproduction, expected behavior and potential impact. Use a test account you control. Do not access other users’ data, disrupt the service, exfiltrate credentials or publish sensitive details before coordination.
Scope and expectations
This page is not a bug-bounty offer, a security certification or an authorization to attack third-party networks. Token-storage controls and other safeguards in an existing connected application must be assessed separately from this website scaffold. No system is guaranteed to be completely secure.
Let’s get you to the right place.
For questions about this page, contact support@laheef.dev. Please do not include passwords, API keys or payment-card details.
Contact the team