Email inboxes for AI agents.
- Implementation fingerprint
- custom 35% confidence
- Fingerprint evidence
- valid 402 Payment challenge observed without implementation-specific marker
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 12:38 PM UTC
- Origin
- https://mpp.api.agentmail.to
- Tags
- emailinboxesdomainsdraftsthreadswebhooksmessaging
Payment surface
154 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
This bounded detail view shows 25 endpoints. Continue with the next API page or the endpoint index.
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- 0x6e3184C204e596dED89E8A5693B602097F4Ab687
- Chain
- 4217
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Probe coverage
309 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 9, 2026, 12:38 PM UTCGET https://mpp.api.agentmail.to/v0/drafts/:draft_id/attachments/:attachment_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:21 PM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 9, 2026, 6:29 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads/:thread_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:19 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts/:draft_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 6:18 AM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 9, 2026, 12:44 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:26 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/metrics
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:25 AM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 8, 2026, 6:39 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts/:draft_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:25 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads/:thread_id/attachments/:attachment_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:25 PM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 8, 2026, 12:36 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads/:thread_id/attachments/:attachment_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts/:draft_id/attachments/:attachment_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/drafts
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts/:draft_id/attachments/:attachment_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 PM UTCGET https://mpp.api.agentmail.to/v0/lists/:direction/:type/:entry
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/drafts
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:24 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id/raw
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:23 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id/attachments/:attachment_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:23 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:19 PM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 8, 2026, 6:35 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/inboxes/:inbox_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:23 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains/:domain_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:23 AM UTCGET https://mpp.api.agentmail.to/v0/domains/:domain_id/zone-file
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:22 AM UTCGET https://mpp.api.agentmail.to/v0/threads/:thread_id/attachments/:attachment_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/threads/:thread_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/lists/:direction/:type
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/lists/:direction/:type/:entry
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 6:21 AM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 8, 2026, 12:38 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/domains/:domain_id/zone-file
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:25 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/metrics
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:21 AM UTCGET https://mpp.api.agentmail.to/v0/domains/:domain_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:21 AM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/lists/:direction/:type/:entry
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:20 AM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/inboxes
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:20 AM UTCGET https://mpp.api.agentmail.to/v0/drafts/:draft_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 8, 2026, 12:20 AM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 7, 2026, 6:37 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/api-keys
HTTP 40492 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:23 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id/messages/:message_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:23 PM UTCGET https://mpp.api.agentmail.to/v0/inboxes/:inbox_id
HTTP 40391 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:22 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/lists/:direction/:type
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:20 PM UTCGET https://mpp.api.agentmail.to/v0/pods/:pod_id/threads
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:20 PM UTCGET https://mpp.api.agentmail.to/v0/threads/:thread_id
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:20 PM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 7, 2026, 12:35 PM UTCGET https://mpp.api.agentmail.to/v0/lists/:direction/:type
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 12:20 PM UTCGET https://mpp.api.agentmail.to/
scanner stopped: cross-host-redirectCross-host redirect to https://agentmail.to/ was recorded but not followed
Oct 7, 2026, 6:42 AM UTCGET https://mpp.api.agentmail.to/v0/pods
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:24 AM UTCGET https://mpp.api.agentmail.to/v0/webhooks
HTTP 402192 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 7, 2026, 6:22 AM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
probe_safety
Observedcross-host-redirect: Cross-host redirect to https://agentmail.to/ was recorded but not followed
Basis: scanner policy decision · Oct 9, 2026, 12:38 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:21 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:19 AM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:19 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:19 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 6:19 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:19 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:19 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:19 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:19 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:19 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 6:18 AM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 6:18 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 6:18 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 6:18 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 6:18 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 6:18 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 6:18 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 6:18 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:26 AM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:26 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:26 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:26 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:26 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:26 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:26 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:26 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:26 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:25 AM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:25 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:25 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:25 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 9, 2026, 12:25 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:25 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:25 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:25 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:25 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:25 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:25 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:25 PM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 6:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:25 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:25 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:25 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:25 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:25 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:25 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:25 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:25 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:24 PM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:24 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:24 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:24 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:24 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:24 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:24 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:24 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:24 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 PM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:23 PM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 12:19 PM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 12:19 PM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 12:19 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 PM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 12:19 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 12:19 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 12:19 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 12:19 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 12:19 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 12:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:23 AM UTCbounded_response
Tested — pass91 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 8, 2026, 6:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 8, 2026, 6:23 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 8, 2026, 6:23 AM UTCbounded_response
Tested — pass192 bytes within scanner limit
Basis: harmless scanner · Oct 8, 2026, 6:23 AM UTCchallenge_parse
Tested — pass1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 8, 2026, 6:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 8, 2026, 6:23 AM UTCeconomic_exposure_metadata
Unknown[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 8, 2026, 6:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 8, 2026, 6:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 8, 2026, 6:23 AM UTC— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"92 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"140694 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:bounded_response: {"state":"tested-pass","evidence":"140694 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"92 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property