PalworldHelper handles server credentials and player save data. Do not report security issues in public issues.
Until a private reporting address is published, contact the repository owner directly through GitHub. Do not include real credentials, private keys, or save files in reports.
Secrets must be stored through a protected local credential mechanism in production. Plain-text passwords in configuration files are not an accepted final implementation.