Contact

Get in touch

Bug reports are the most useful thing you can send, particularly ones that include the input that triggered the problem. Use the form below, and see the guidance alongside it for what to include.

Send a message


Only used to reply to you. It is not added to any list.

For a bug, naming the tool here helps, for example “CSV to JSON drops a column”.

What you did, what you expected, and what happened instead. Please do not include real credentials or production data. Up to 5,000 characters.

What you type here is stored so it can be read and replied to, unlike the tools, which process your data in the browser and store nothing. Nothing you have converted is attached to this message.

Security issues


If you believe you have found a vulnerability (a cross-site scripting vector in a tool's output, a way to make a parser read something it should not, or a content-security-policy bypass) please report it privately first rather than publishing it, and allow time for a fix.

Include the URL, the input, and what the input causes to happen. A proof of concept that demonstrates the issue in a browser is ideal.

Reports about the classes of problem these tools already defend against (entity expansion, prototype pollution, catastrophic regular expressions) are still welcome if you find a case that gets through.

Requesting a tool


Requests that describe a real task are the ones that get built. What are you converting, what do you do with the result, and what makes the existing tools insufficient? That is much more actionable than a format pair on its own.

Some conversions are deliberately absent because they are not meaningful, a pair of formats with no sensible mapping between them produces a page that looks like a tool and is not one. If something obvious seems missing, it is worth asking why.

Before requesting, it is worth checking the full list, since a tool may exist under a name you did not search for.

Common questions


Will you see the data I was converting?
No. The tools process your data in your browser without uploading the input or output, and the contact form submits only the four fields you fill in. If a bug depends on specific input, you have to paste a sample into the message yourself, and you should reduce it to the smallest example that still reproduces the problem first.
How long does a reply take?
There is no service-level agreement to quote. Messages are read, and reports of a conversion producing silently wrong output are looked at ahead of everything else, because a wrong answer with no error is the most damaging kind of bug on a site like this.
Can I request a new tool?
Yes, and the requests that get built are the ones describing a real task: what you are converting, what you do with the result, and why the existing tools do not cover it. A bare format pair is much harder to act on, and some pairs are deliberately absent because no sensible mapping exists between them.
How should I report a security issue?
Privately, and before publishing it. Include the URL, the input, and what the input causes to happen. A proof of concept that demonstrates the issue in a browser is ideal. Please allow time for a fix before any disclosure.
Contact | NuvTool