Missing User Warnings
Low
- Confidence
- 84% confidence
- Finding
- The Aviationstack API key is placed in the query string, which can be exposed through logs, proxies, browser/history-like tooling, or upstream telemetry even though the transport is HTTPS. In this script the exposure is limited because the endpoint itself expects this parameter, but transmitting credentials in URLs still increases accidental secret leakage risk.
