JW
Dossier Research
Hire me
Security researcher
Justin Willhite

Justin Willhite

@thejdubb02

Independent security researcher. I read source to find real, reproducible vulnerabilities in open-source software, then disclose them responsibly and ship minimal, tested fixes. Focus on access-control and IDOR flaws, server-side request forgery, and injection.

Available for small, focused source reviews and coordinated disclosure, justin@itsjustin.me

01

By the numbers

29Merged open-source PRs
13External projects
160KGitHub stars reached
78%Pull requests accepted
02

Impact at a glance

Project reach

GitHub stars of every project with a merged fix, showing the work lands in large, widely used software.

open-code-review 42.6k changedetection.io 34.7k github-mcp-server 33.3k ConvertX 19.1k kaneo 9.3k google-maps-scraper 6.2k qui 4.6k Dispatcharr 4.2k SnapOtter 2.8k webmail 1.2k multiplatform-markdown-renderer 1.1k bindery 478 Dashboarr 353

Merge momentum

Cumulative merged pull requests over time.

0 14 29 Aug 27, 2026 Sep 25, 2026

Language mix

Merged pull requests by each project's primary language.

15 9 3
TypeScript 15 Go 9 JavaScript 3 Python 1 Kotlin 1
03

Selected work

Merged

changedetection.io

#4336 Browser Steps picker cannot select a <select> nested in a <div>
Merged

github-mcp-server

#3221 Return a clear error for missing owner/repo/issue_number in the copilot assignment tools
Merged

qui

#2671 Serve a static favicon so Firefox background tabs are not blank #2648 Fold Unicode in CONTAINS_IN name matching #2558 Resume fast verification rechecks that finish between polls
Merged

bindery

#2503 Show excluded books correctly on the series view (#2324) #2317 Only save latin alternate-name aliases for a non-latin author (#2268) #2310 Exclude hidden books from series fill and genre apply (#2302)
Merged

kaneo

#1719 Add a change-password screen under account settings
Merged

Dispatcharr

#1665 Serve the logo cache to image/* clients instead of 406 (#1541) #1664 Keep a blank provider name from discarding the whole import batch (#1586) #1642 Fix VOD category filter mis-splitting names that contain '|' (#1603)
Merged

open-code-review

#1162 Honor timeout_sec for openai-go's ResponseHeaderTimeout (#1161)
Merged

SnapOtter

#1053 Log the caught error when an audit write or HMAC step fails (#1012) #1052 Validate TRUST_PROXY list at env-parse time instead of crashing Fastify (#999) #1051 Stop self-hosted instances sending heatmap and dead-click data to PostHog #994 Classify a qpdf password-probe timeout as a 4xx, not a 500 (#982) #993 Trim group displayName so whitespace twins are duplicates (#988)
Merged

webmail

#997 Normalize discovery base so a session JMAP_SERVER_URL can refresh (#971)
Merged

ConvertX

#637 Apply EXIF auto-orient so portrait images don't convert sideways (#590) #629 Raise execFile maxBuffer so long conversions don't overflow stderr
Merged

multiplatform-markdown-renderer

#627 Render GFM math spans as text instead of dropping them
Merged

Dashboarr

#402 Remember the last-used add config per instance (#341) #398 Show swarm seeds and leechers on each tile #397 Let the Downloads and Usenet queue sorts be reversed #396 Mark season premieres on the calendar and event rows #393 Name the host and mention certificates on https transport failures #392 Add Maintainerr integration
Merged

google-maps-scraper

#330 Gmaps: keep the /maps/place/ marker when a place URL has a ".." segment
Coordinated

Disclosures in progress

Source-review findings, including access-control (IDOR) and server-side request forgery issues, reported to the affected projects through their security advisory and disclosure channels. Details published once fixed.

04

Focus areas

Access control and IDOR SSRF Injection White-box source review Responsible disclosure
05

Find me