The dashboard paints revenue and churn metrics on page load without any gating or scope reduction.
CWE-200
CWE-306
fetch("/api/metrics").then(renderRevenue)