Please report suspected vulnerabilities through GitHub → Security → Report a vulnerability for this repository. Avoid posting private tokens, exact coordinates or exploitable details in a public issue.
The latest release is the focus of fixes; this small community project does not promise a response deadline or long-term support for older versions.
The card runs in the Home Assistant frontend and uses the existing hass object for weather data. It does not need a separately configured access token. External requests send only the feature inputs described in the README, such as search text or rounded coordinates. Provider text is rendered as escaped text. Generated installation ZIPs contain the installed public assets, not browser preferences or Home Assistant configuration.
If you accidentally publish a Home Assistant token, revoke it in Home Assistant rather than relying on deleting the post.