Security fixes are applied to the latest version on the default branch.
Report vulnerabilities privately to sunny.sudarshan@gmail.com. Do not open a public issue containing exploit details, credentials, or personal data.
Include the affected file or URL, reproduction steps, impact, and any suggested mitigation. Reports will be acknowledged as soon as practical.
WindowWars is a static, client-only project. It has no backend, authentication, database, analytics, third-party dependencies, remote assets, or data collection. The production artifact includes a restrictive Content Security Policy and recommended static-host security headers.