CDN-hosted third-party scripts (analytics, chatbots, A/B testing)
Risk: scripts loaded from third-party CDNs run with full DOM access on the host page. If the CDN file is tampered (as with Ticketmaster/Inbenta), the script can access and exfiltrate any data on the page — form fields, session tokens, payment card data. No API call is needed — just trust in the CDN URL.