Please do not file public issues for suspected vulnerabilities. Report them privately to the repository owner with reproduction steps and impact.
This is a portfolio project; credentials belong only in local environment files and must never be committed.