Skip to content

Security: alirezach/TrueCost

Security

SECURITY.md

Security Policy

Reporting Vulnerabilities

If you discover a security vulnerability in True Cost, please report it via GitHub Issues. Do not disclose vulnerabilities publicly.

Minimal Permissions Design

True Cost uses the minimum permissions necessary:

  • storage – to save your wage and display settings locally
  • activeTab – to inject the price picker on the current tab only
  • scripting – to run the picker script on demand

No broad host permissions (<all_urls>) are requested. Content scripts are only injected on the specific sites listed in the manifest.

Data Safety

  • All data stays in your browser (chrome.storage.sync / chrome.storage.local)
  • The only outbound traffic is plain GET downloads of public data files from the project's own GitHub repository (wage dataset + site selector database); see PRIVACY.md for the exact list and schedule
  • No user browsing data is collected or transmitted

There aren't any published security advisories