EPISODE · Jun 19, 2026 · 10 MIN
How Your Web App Leaks User Data via Third-Party Scripts
from The Web Development Podcast with Fexingo: Frontend, Backend, and Modern Web Stack · host Fexingo
Episode 60 of The Web Development Podcast digs into a hidden privacy & performance issue: third-party scripts that exfiltrate user data from your web app in plain sight. Lucas and Luna use a real-world case—a mock e-commerce site loading a tracking script from a seemingly reputable CDN—to show how a single fetch call can silently leak browsing history, cart contents, and even keystrokes. They walk through code examples using the Network tab, explain how subresource integrity (SRI) fails when scripts are dynamically appended, and demonstrate a fix using Content Security Policy (CSP) with script-src and nonce. The episode also covers how to audit existing dependencies with tools like Lighthouse and Sentry. No alarmism—just practical steps to protect users. If today's tech conversation gave you something usable, consider supporting the show at buy me a coffee dot com slash fexingo. #ThirdPartyScripts #DataLeak #WebSecurity #ContentSecurityPolicy #SubresourceIntegrity #CSP #SRI #Privacy #JavaScript #WebDev #Frontend #Performance #Audit #Lighthouse #Sentry #Technology #FexingoBusiness #BusinessPodcast Keep every episode free: buymeacoffee.com/fexingo
Embed this episode
NOW PLAYING
How Your Web App Leaks User Data via Third-Party Scripts
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.