I think you misunderstood me here,
PWAs can be very easily injected with scripts, which can run unauthorized code onve permissions are granted, which will create a scenario where we will revert to a "verification process" and we are back to walled gardens

PWAs can be very easily injected with scripts

Try injecting scripts into a HTTPS connection, which PWAs must use.

hi mao,

here I created a detailed step by step article for creation in PWA. I guess this will help

