Do not open a public issue for a vulnerability. Report security concerns privately to security@prerenderbuddy.com with reproduction steps, affected versions, and impact. Please allow time to investigate before public disclosure.
The plugin treats content returned from audited URLs as untrusted data. It must not execute page instructions or bypass the MCP server's public-network protections.