Justin Willhite
Independent security researcher. I read source to find real, reproducible vulnerabilities in open-source software, then disclose them responsibly and ship minimal, tested fixes. Focus on access-control and IDOR flaws, server-side request forgery, and injection.
Available for small, focused source reviews and coordinated disclosure, justin@itsjustin.me
By the numbers
Impact at a glance
Project reach
GitHub stars of every project with a merged fix, showing the work lands in large, widely used software.
Merge momentum
Cumulative merged pull requests over time.
Language mix
Merged pull requests by each project's primary language.
Selected work
changedetection.io
#4336 Browser Steps picker cannot select a <select> nested in a <div>github-mcp-server
#3221 Return a clear error for missing owner/repo/issue_number in the copilot assignment toolskaneo
#1719 Add a change-password screen under account settingsopen-code-review
#1162 Honor timeout_sec for openai-go's ResponseHeaderTimeout (#1161)SnapOtter
#1053 Log the caught error when an audit write or HMAC step fails (#1012) #1052 Validate TRUST_PROXY list at env-parse time instead of crashing Fastify (#999) #1051 Stop self-hosted instances sending heatmap and dead-click data to PostHog #994 Classify a qpdf password-probe timeout as a 4xx, not a 500 (#982) #993 Trim group displayName so whitespace twins are duplicates (#988)webmail
#997 Normalize discovery base so a session JMAP_SERVER_URL can refresh (#971)multiplatform-markdown-renderer
#627 Render GFM math spans as text instead of dropping themDashboarr
#402 Remember the last-used add config per instance (#341) #398 Show swarm seeds and leechers on each tile #397 Let the Downloads and Usenet queue sorts be reversed #396 Mark season premieres on the calendar and event rows #393 Name the host and mention certificates on https transport failures #392 Add Maintainerr integrationgoogle-maps-scraper
#330 Gmaps: keep the /maps/place/ marker when a place URL has a ".." segmentDisclosures in progress
Source-review findings, including access-control (IDOR) and server-side request forgery issues, reported to the affected projects through their security advisory and disclosure channels. Details published once fixed.