Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation instructs users to enable Everything's HTTP server but does not prominently warn that exposing file-search results over HTTP can reveal sensitive filenames, paths, and metadata. Even when bound locally, other local processes or misconfiguration could query the API, and if the server is reachable beyond localhost the privacy impact increases significantly.
