Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The tracking helper rewrites all HTTP(S) links in outgoing email HTML to append UTM parameters automatically, without any filtering, consent guidance, or allowlist. This can unintentionally modify sensitive links such as signed URLs, password reset links, unsubscribe links, or third-party URLs, potentially breaking security-sensitive flows, leaking identifiers into logs/analytics systems, or undermining privacy expectations.
