Missing User Warnings
Medium
- Confidence
- 92% confidence
- Finding
- The script automatically issues HTTP requests for every extracted link, including external third-party URLs, without requiring explicit user acknowledgment or offering a safe/offline mode. In practice this can leak network metadata such as source IP, user agent behavior, and audit timing to arbitrary hosts referenced in local HTML, and can be abused as an SSRF-style network probe if untrusted HTML content is scanned in a sensitive environment.
