
Samsung was tested and 132 issues were detected across the site. The most critical finding was: API key exposed in URL query parameter to external service (ipfind). Issues span Security, A11y, Performance, Other categories. Persona feedback rated Content highest (7/10) and Accessibility lowest (4/10).







Network log shows API key in URL query parameter 'auth' for ipfind.com/me.GET https://api.ipfind.com/me?auth=7fe9ffcc-b476-4e4f-a363-d3a659a31f44 - Status: N/A[LOG] [e] Getting consent for category ID: 4 with notice behavior: opt-out
[LOG] [e] Using TrustArc consent model. Checking consent model: opt-out
[LOG] [e] Is implied location: true
[LOG] [e] Checking consent status for ID: 4, isImpliedLocation: true and prefCookie: JSHandle@object
[LOG] [e] No consent decision found, using implied location: truehttps://api2.sprinklr.com/api/v2/deflect
https://prod-samsung-live-chat.sprinklr.com[ERROR] The source list for the Content Security Policy directive 'default-src' contains an invalid source: 'https:*.sprinklr.com'. It will be ignored.