| Version | Supported |
|---|---|
| 1.1.x | ✅ |
| ≤ 1.0.9 | ❌ |
Versions at or below 1.0.9 contain defects that cause the library to report false WCAG compliance. They are not supported — please upgrade. See the changelog for details.
Report security issues privately through GitHub Security Advisories.
Please do not open a public issue for a security report.
This is a small library maintained by one person; expect an initial response within a week. If you have not heard back after two weeks, feel free to open a public issue saying only that you are awaiting a response on a private report — without details.
The package has no runtime dependencies, performs no I/O, and makes no network requests, so its attack surface is limited to the correctness and resource use of pure functions. Relevant reports include:
- Input that causes unbounded execution or excessive memory use (for example a value that makes an internal search fail to terminate).
- Input that causes a thrown exception rather than a
nullreturn. - Any input that produces a false compliance verdict — a pair reported as
meeting a WCAG threshold that does not. This is treated as a security-class
issue because the library's output is used to make accessibility claims, and
a wrong
truecan carry legal and regulatory consequences downstream.