Three browser-side questions decide most of the risk. Obfuscation is relevant to none of the first, some of the second, and all of the third.
What reaches the browserAnd where it rests afterwards — storage, URLs, caches, error reports.
What executes alongside itEvery tag on an authenticated page has full access to that page.
Who receives whatEvery data and source flow needs an owner and an agreement.