It reads four things and sends one
You can check every claim on this page against the source, which is the whole argument for an open tool. What follows is the boundary, the history, and the way to tell us we got it wrong.
Report something you found
A named team reads this address, acknowledges inside one working day and agrees a disclosure date with you. We do not ask for silence beyond the fix, and we credit you unless you ask us not to.
Contact: mailto:security@example.org
Encryption: https://example.org/pgp-key.txt
Preferred-Languages: en, de
Policy: https://example.org/security
Expires: 2027-08-15T00:00:00.000Z
Its reach
Three things, and one of them leaves the machine. Stated as a table rather than as prose, because this is the section somebody copies into a procurement questionnaire.
| What it touches | Access | When | What survives |
|---|---|---|---|
| your project directory | read | while a tool answers | nothing |
| the bundled index | read | always available | ships with the release |
| docs.typo3.org | one host, read | only on a call to that tool | nothing |
Read means read: the process has no write path into your tree, which is checkable in the source rather than promised here. The bundled index comes from public sources once per release and is the only thing that answers when nothing else is reachable — and it says so in the answer. A single tool fetches the one host, only when that tool is the one called.
Nothing survives between runs: no account, no log of the questions, no cache of your project. This is why there is nothing here to export and nothing to delete — the process ends and takes its memory with it.
The one line that leaves
Drawn rather than described, because “it only calls out for documentation” is the kind of sentence a reader has to take on trust. The single outbound path is the exception in the picture, and it only reads.
Every advisory, including the slow one
Three so far, with the time from report to fix beside each. The nine days on the first one is in the table for the same reason the other two are: a history with the bad entry taken out is not a history.
| Advisory | Affects | Fixed in | Reported to fixed | Severity |
|---|---|---|---|---|
| SA-2026-003 | 1.3.0 – 1.3.2 | 1.3.3 | 4 days | low |
| SA-2026-002 | 1.2.0 – 1.2.4 | 1.2.5 | 2 days | moderate |
| SA-2025-001 | 1.0.0 – 1.1.1 | 1.1.2 | 9 days | high |
An advisory comes out after a fix is available and never before. Every one of them names the versions affected rather than the ones fixed, because a reader checks what they run.
For the questionnaire
The four answers procurement asks for, given here rather than in a form somebody has to request. None of them changes per customer, which is why none of them is behind a contact form.
The tool runs as a subprocess of your editor, on your machine. There is no service to host, no region to choose and no subprocessor to name.
It reads code and package metadata. Where a project’s own files contain personal data, they are read and not retained — nothing is written and nothing is sent.
No state survives the process. There is no log of the questions, which is also why we cannot produce one for an audit.
The published source is the source that runs. There is no separate build for anyone, and no clause that changes for a paying reader.