Report suspected vulnerabilities privately through GitHub Security Advisories after the standalone repository is created. Do not open a public issue for an unpublished vulnerability.
The plugin analyzes source text and resolves import paths but does not execute linted project code. Security reports should include a minimal ESLint configuration, source fixture, observed behavior, and affected version.