How bizarre. The thief has already deleted the thread. So obviously guilty just by the fact that it's clearly a browser app inside a desktop wrapper. That makes absolutely no sense as an architecture decision. And it uses all of Photopea's libraries. Before the thread was deleted, they had spawned a few sub‑agents to come in and bully the Photopea creator. But none of it was believable; it was clearly an angry thief lashing out.
No, I have a family and this is a hobby. I don't need threats or online bullying.
I'll do a code audit (and you should too, before casting stones). The code is there.
That makes absolutely no sense as an architecture decision.
It makes a lot of sense architecturally. It's much simpler to update a webpage than force every user to update their app when something needs to change. Consequently a lot of apps, especially on mobile, use a system webview with a page loaded from a server and rendered to look like the app for anything that gets regular updates. The alternative is having lots of versions of the page and needing to manage all the different variations of payloads from them.
Backwards compatibility in an API isn't that hard, but when there's a simpler option (a webview) people will take it.
That said, if there's no native stuff in the app, it is a bit harder to justify.