Application safeguards
File extensions are not trusted. Parsers validate segment and chunk boundaries, metadata is rendered as text, SVG is not accepted as an image input, and CSV exports neutralize spreadsheet formulas.
- 25 MiB and 80 MP limits
- Worker isolation for parsing
- Sanitized download names
- No innerHTML for metadata
- Security headers in hosted responses
Report a security issue
Send a concise description to security@analyzeimage.com when the public mailbox is activated. Include reproduction steps and impact, but do not attach a private user image, credentials or secrets. No bug bounty is currently promised.