Missing User Warnings
Medium
- Confidence
- 91% confidence
- Finding
- The guide explicitly instructs users to place AppKey and AppSecret in a plaintext local config file but provides no warning about secret handling, file permissions, backups, or source-control exposure. While local configuration of credentials can be legitimate, omitting basic secret-safety guidance increases the risk that users will store long-lived credentials insecurely and leak them through logs, screenshots, backups, or accidental commits.
