authorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:25 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:25 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:25 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:25 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:23 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:23 PM UTCbounded_response
Tested — pass48198 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:22 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:21 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:20 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:24 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:24 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:23 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTCbounded_response
Tested — pass0 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCShowing a bounded 250 of 1,346 security-property records.