Safe browsing and reporting
JevHunt hosts a directory, not executable downloads. Community project links are limited to GitHub repositories and README evidence so visitors can inspect the source before using a project.
Last updated: September 21, 2026
JevHunt will never ask for your Google password, recovery code, private repository token, JEV API key or payment details. A request for any of these should be treated as suspicious.
Controls in place
- HTTPS with HSTS, restrictive security headers and a Content Security Policy.
- Server-side OAuth sessions stored as one-way token hashes in Cloudflare D1.
- Single-use, expiring OAuth state values to prevent login CSRF.
- Same-origin redirect validation after Google sign-in.
- Submission authentication, validation and rate limiting.
- README-based catalog verification and no direct links to unreviewed project websites.
Using community projects
A verified JEV reference is not a security audit. Read the repository, inspect release artifacts, review requested permissions and use an isolated environment when evaluating unfamiliar code. GitHub and project authors control repository content after it is listed.
Report a vulnerability
Use the repository's Security page for responsible reporting guidance. If private reporting is unavailable, open a minimal GitHub issue without exploit details or personal data so a maintainer can arrange a private channel.
Report deceptive content
Report a suspicious listing, misleading claim or unsafe repository through the issue tracker. Include the JevHunt listing name and GitHub repository URL. Do not visit or attach suspected payloads.