Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The document includes realistic-looking plaintext secrets such as a database password and JWT secret directly in sample configuration without clearly labeling them as placeholders or warning against copying them into production. In a migration guide, readers may reuse these examples verbatim, normalizing insecure secret handling and increasing the chance that credentials are committed to source control or deployed unchanged.
