Missing User Warnings
Medium
- Confidence
- 98% confidence
- Finding
- The script places the API key and user query parameters into a request sent over plain HTTP, not HTTPS. This exposes the credential and request contents to interception or modification by any network attacker between the client and the API endpoint.
