Topic: Attention admin

Hi admin

Please Close API feature

http://heedyou.com/docs/files/examplejs.html

Probably people can create XSS code on api feature. I advice close this section

Best Regards

Re: Attention admin

Thanks for your concern but there is no reason to worry.

The only parameter that allows the kind of characters necessary is a name field, and it is being run through htmlentities function before being passed through. There is no way for it to execute as a code on the other end.

Best regards,
HeedYou