Please do not open a public issue for security problems. Use GitHub's private vulnerability reporting instead, with steps to reproduce and the impact you expect.
- Protect
/adminwith Cloudflare Access, or use a long randomADMIN_PASSWORD. - Store
SMTP_PASS,ADMIN_PASSWORDandTURNSTILE_SECRET_KEYas Worker secrets, never inwrangler.jsonc. - Give each site its own form so API keys can be rotated independently.
- Set a retention period on every form that matches the site's privacy policy.