ExplorerCanvas runs native code inside explorer.exe; treat crashes, unsafe DLL
loading, registry overreach, and path disclosure as security-sensitive.
Do not publish exploit details in a public issue. Report privately to the project maintainer with the Windows build, Explorer version, reproduction steps, and a sanitized log. Logs intentionally sanitize user paths; review them before sharing.
Only the latest source revision is supported. No Windows build is considered verified until its runtime checklist has passed.