Findings
This plugin displays HTML obtained via an API call to app.advisories.dxw.com, making it possible that dxw could perform an XSS attack against an admin when this plugin is enabled.
NB: We will, of course, not do this. We’re thinking about how we can change the structure of the API so that we can escape all the data we get from it before it’s displayed.