Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation advises storing a long-lived bearer access token in a local file but does not warn that the token is effectively a credential tied to a site and should be protected like a secret. If saved insecurely, other local users, malware, backups, logs, or tooling could recover the token and gain ongoing read access to non-public analytics data.
