Missing User Warnings
Low
- Confidence
- 80% confidence
- Finding
- The page imports executable JavaScript from a remote CDN at runtime without any disclosure, which creates a supply-chain trust dependency and causes user data such as IP address and request metadata to be sent to a third party. If the CDN, package, or delivery path is compromised, opening the local HTML file could execute attacker-controlled code in the browser.
