Honestly, it is also surprising that this issue is only being noticed now.
Exposing an API key in client-side JavaScript is a very basic security risk, so it feels like something that should have been caught much earlier.
API Key Exposure Security Risk in Client-Side JavaScript
By
–