| Version | Supported |
|---|---|
| current | β Yes |
| older | β No |
SlowQ is a tiny utility that runs with Accessibility privileges β that makes security extra important.
If you find a vulnerability:
- Do not open a public GitHub issue
- Email the maintainer or reach out privately
- Include a clear description and reproduction steps
- Escalation of privileges via the event tap
- Keystroke leakage or logging
- Bypassing the confirmation gate
- Injection via synthetic events
The Sources/ directory. The Info.plist and build configuration are assumed to be as-shipped.
You should expect an acknowledgment within 72 hours, and a fix timeline depending on severity.
SlowQ stores its settings in UserDefaults (standard com.slowq.SlowQ domain). No data leaves your machine.
Thank you for helping keep SlowQ safe. π