authorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 PM UTCbounded_response
Tested — pass326 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:26 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:26 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:26 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:26 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 PM UTCapi_catalog_parse
ObservedNo RFC 9727 API catalog was available at this URL (HTTP 404); prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Oct 8, 2026, 12:26 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:26 AM UTCbounded_response
Tested — pass79 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:26 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:26 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:26 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:26 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:26 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:26 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:26 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:26 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:26 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:26 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:26 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:26 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:26 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 AM UTCbounded_response
Tested — pass79 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:25 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 7, 2026, 6:25 PM UTCbounded_response
Tested — pass79 bytes within scanner limit
Basis: harmless scanner · Oct 7, 2026, 6:25 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 7, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:25 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 7, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 7, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 7, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 7, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 7, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 7, 2026, 6:25 PM UTCopenapi_parse
Tested — pass36 payment offer(s) accepted
Basis: harmless discovery response · Oct 7, 2026, 12:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:22 AM UTCbounded_response
Tested — pass362 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 12:22 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 1, 2026, 12:22 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 12:22 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 12:22 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:22 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 1, 2026, 12:22 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 12:22 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 12:22 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 12:22 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 12:22 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 12:22 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:22 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:22 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 30, 2026, 6:19 PM UTCbounded_response
Tested — pass312 bytes within scanner limit
Basis: harmless scanner · Sep 30, 2026, 6:19 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Sep 30, 2026, 6:19 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Sep 30, 2026, 6:19 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Sep 30, 2026, 6:19 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 30, 2026, 6:19 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Sep 30, 2026, 6:19 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Sep 30, 2026, 6:19 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Sep 30, 2026, 6:19 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Sep 30, 2026, 6:19 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Sep 30, 2026, 6:19 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Sep 30, 2026, 6:19 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 30, 2026, 6:19 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Sep 30, 2026, 6:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 28, 2026, 6:18 AM UTCbounded_response
Tested — pass79 bytes within scanner limit
Basis: harmless scanner · Sep 28, 2026, 6:18 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Sep 28, 2026, 6:18 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Sep 28, 2026, 6:18 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Sep 28, 2026, 6:18 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 28, 2026, 6:18 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Sep 28, 2026, 6:18 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Sep 28, 2026, 6:18 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Sep 28, 2026, 6:18 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Sep 28, 2026, 6:18 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Sep 28, 2026, 6:18 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Sep 28, 2026, 6:18 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 28, 2026, 6:18 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Sep 28, 2026, 6:18 AM UTC