Old OVH DNS Update API credentials exhibit insecure behaviour

When targeting the older api to update DNS records, i noticed something that i'd consider slightly security relevant, where is the best place to report something like that?