Contact
Get in touch
Bug reports are the most useful thing you can send, particularly ones that include the input that triggered the problem. Use the form below, and see the guidance alongside it for what to include.
Send a message
Security issues
If you believe you have found a vulnerability (a cross-site scripting vector in a tool's output, a way to make a parser read something it should not, or a content-security-policy bypass) please report it privately first rather than publishing it, and allow time for a fix.
Include the URL, the input, and what the input causes to happen. A proof of concept that demonstrates the issue in a browser is ideal.
Reports about the classes of problem these tools already defend against (entity expansion, prototype pollution, catastrophic regular expressions) are still welcome if you find a case that gets through.
Requesting a tool
Requests that describe a real task are the ones that get built. What are you converting, what do you do with the result, and what makes the existing tools insufficient? That is much more actionable than a format pair on its own.
Some conversions are deliberately absent because they are not meaningful, a pair of formats with no sensible mapping between them produces a page that looks like a tool and is not one. If something obvious seems missing, it is worth asking why.
Before requesting, it is worth checking the full list, since a tool may exist under a name you did not search for.
Common questions
- Will you see the data I was converting?
- No. The tools process your data in your browser without uploading the input or output, and the contact form submits only the four fields you fill in. If a bug depends on specific input, you have to paste a sample into the message yourself, and you should reduce it to the smallest example that still reproduces the problem first.
- How long does a reply take?
- There is no service-level agreement to quote. Messages are read, and reports of a conversion producing silently wrong output are looked at ahead of everything else, because a wrong answer with no error is the most damaging kind of bug on a site like this.
- Can I request a new tool?
- Yes, and the requests that get built are the ones describing a real task: what you are converting, what you do with the result, and why the existing tools do not cover it. A bare format pair is much harder to act on, and some pairs are deliberately absent because no sensible mapping exists between them.
- How should I report a security issue?
- Privately, and before publishing it. Include the URL, the input, and what the input causes to happen. A proof of concept that demonstrates the issue in a browser is ideal. Please allow time for a fix before any disclosure.