Missing User Warnings
Medium
- Confidence
- 93% confidence
- Finding
- The manifest requires a token to be sent as a query parameter to an external API, but it provides no user-facing disclosure about credential handling, third-party transmission, or logging exposure. Query-string tokens are particularly risky because they may be captured in logs, proxies, browser histories, or monitoring systems, increasing the chance of credential leakage.
