Plainly is a read-only menu bar app: it reads battery data through public IOKit APIs, makes no network calls, and stores nothing outside its own process. The attack surface is intentionally small — but if you find something, please tell me.
Preferred: GitHub's private vulnerability reporting on this repo (Security tab → "Report a vulnerability").
If that route doesn't work for you, open a regular issue saying only that you've found a security-related problem — no details in public — and I'll follow up privately.
Solo maintainer, best effort: acknowledgement within a few days, and a fix as fast as severity warrants. Supported version: latest main / latest release.