Only the latest published FocusPocus release receives security fixes.
Please do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature for this repository. Include reproduction steps, affected versions, and the expected impact.
FocusPocus installs global input hooks to provide its advertised visualization features. Reports involving input handling, password-field detection, update links, installer integrity, or startup persistence are especially useful.