Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The template loads executable and styling dependencies from third-party CDNs, which means the generated HTML is not truly self-contained and its behavior depends on remote infrastructure at runtime. This introduces supply-chain and privacy risk: a compromised CDN, blocked network, or modified remote asset can change script execution, break rendering, or leak access metadata when the file is opened.
