- Recipient
- 0xbe6c07f6fce303483458a7ddc929eb50a8ae6574
- Chain
- 4217
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Read and automate X. Paid reads accept credits. Some lookups accept MPP. Writes require API key or OAuth 2.1. Shared-account reads return public posts only. ## Client Libraries [SDK, CLI, Terraform](https://docs.xquik.com/sdks), [TweetClaw](https://docs.xquik.com/guides/tweetclaw), and [version deprecation](https://xquik.com/deprecation-policy.md).
Payment surface
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
Probe coverage
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
Response exceeds 262144 bytes
Oct 9, 2026, 12:29 PM UTCResponse exceeds 262144 bytes
Oct 9, 2026, 6:25 AM UTCResponse exceeds 262144 bytes
Oct 9, 2026, 12:32 AM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 9, 2026, 12:19 AM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 6:32 PM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 12:29 PM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 6:28 AM UTCResponse exceeds 262144 bytes
Oct 8, 2026, 12:29 AM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 6:29 PM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 12:28 PM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 6:32 AM UTCResponse exceeds 262144 bytes
Oct 7, 2026, 12:37 AM UTCResponse exceeds 262144 bytes
Oct 6, 2026, 6:31 PM UTCResponse exceeds 262144 bytes
Oct 6, 2026, 12:34 PM UTCResponse exceeds 262144 bytes
Oct 6, 2026, 6:24 AM UTCResponse exceeds 262144 bytes
Oct 6, 2026, 12:30 AM UTCResponse exceeds 262144 bytes
Oct 5, 2026, 6:29 PM UTCResponse exceeds 262144 bytes
Oct 5, 2026, 12:28 PM UTCResponse exceeds 262144 bytes
Oct 5, 2026, 6:27 AM UTCResponse exceeds 262144 bytes
Oct 5, 2026, 12:27 AM UTCResponse exceeds 262144 bytes
Oct 5, 2026, 12:19 AM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 2, 2026, 6:21 PM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:20 PM UTC845 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 12:19 PM UTC1,434 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:20 AM UTC420,650 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Oct 1, 2026, 6:20 AM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 29, 2026, 6:19 PM UTC258,743 response bytes · 1 redirect · HTTPS fetch completed with platform certificate validation
Sep 25, 2026, 12:24 PM UTC · Final URL: https://xquik.com/enResponse exceeds 262144 bytes
Sep 25, 2026, 6:26 AM UTCResponse exceeds 262144 bytes
Sep 25, 2026, 12:35 AM UTCResponse exceeds 262144 bytes
Sep 24, 2026, 6:29 PM UTCResponse exceeds 262144 bytes
Sep 24, 2026, 12:27 PM UTCResponse exceeds 262144 bytes
Sep 24, 2026, 6:28 AM UTCResponse exceeds 262144 bytes
Sep 24, 2026, 12:26 AM UTCResponse exceeds 262144 bytes
Sep 23, 2026, 6:28 PM UTCResponse exceeds 262144 bytes
Sep 23, 2026, 12:32 PM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 23, 2026, 12:21 PM UTCResponse exceeds 262144 bytes
Sep 23, 2026, 6:30 AM UTCResponse exceeds 262144 bytes
Sep 23, 2026, 12:34 AM UTCResponse exceeds 262144 bytes
Sep 22, 2026, 6:37 PM UTCResponse exceeds 262144 bytes
Sep 22, 2026, 12:24 PM UTC1,038 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 12:21 PM UTCResponse exceeds 262144 bytes
Sep 22, 2026, 6:30 AM UTC845 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 6:20 AM UTCResponse exceeds 262144 bytes
Sep 22, 2026, 12:31 AM UTC389,177 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 12:26 AM UTC1,434 response bytes · 0 redirects · HTTPS fetch completed with platform certificate validation
Sep 22, 2026, 12:26 AM UTCResponse exceeds 262144 bytes
Sep 21, 2026, 6:30 PM UTCResponse exceeds 262144 bytes
Sep 21, 2026, 12:28 PM UTCResponse exceeds 262144 bytes
Sep 21, 2026, 6:30 AM UTCEvidence model
Every result names its evidence state. Unknown and not tested never mean secure.
response-too-large: Response exceeds 262144 bytes
Basis: scanner policy decision · Oct 9, 2026, 12:29 PM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 9, 2026, 12:19 AM UTC1038 bytes within scanner limit
Basis: harmless scanner · Oct 9, 2026, 12:19 AM UTC1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 9, 2026, 12:19 AM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:19 AM UTC[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 9, 2026, 12:19 AM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 9, 2026, 12:19 AM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 9, 2026, 12:19 AM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 9, 2026, 12:19 AM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 9, 2026, 12:19 AM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 9, 2026, 12:19 AM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 2, 2026, 6:21 PM UTC1038 bytes within scanner limit
Basis: harmless scanner · Oct 2, 2026, 6:21 PM UTC1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 2, 2026, 6:21 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 6:21 PM UTC[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 2, 2026, 6:21 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 2, 2026, 6:21 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 2, 2026, 6:21 PM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 2, 2026, 6:21 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 2, 2026, 6:21 PM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 2, 2026, 6:21 PM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 6:20 PM UTC1038 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 6:20 PM UTC1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validated
Basis: unauthenticated HTTP response · Oct 1, 2026, 6:20 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:20 PM UTC[{"method":"tempo","intent":"charge","deposit":null,"authorizationWindow":null,"depositWindowRatio":null,"observableAuthorizationExposure":null,"note":"unknown: session authorization inputs not observable"}]
Basis: observable challenge values only · Oct 1, 2026, 6:20 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 6:20 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 6:20 PM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 6:20 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 6:20 PM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 6:20 PM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Oct 1, 2026, 12:19 PM UTC845 bytes within scanner limit
Basis: harmless scanner · Oct 1, 2026, 12:19 PM UTCNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Oct 1, 2026, 12:19 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:19 PM UTCNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Oct 1, 2026, 12:19 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Oct 1, 2026, 12:19 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTCResponse was JSON but not a bounded supported OpenAPI 3 document
Basis: harmless discovery response · Oct 1, 2026, 12:19 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Oct 1, 2026, 12:19 PM UTC0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Oct 1, 2026, 12:19 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Oct 1, 2026, 12:19 PM UTC1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Oct 1, 2026, 12:19 PM UTC3 OpenAPI link(s) accepted
Basis: RFC 9727 discovery response · Oct 1, 2026, 6:20 AM UTCRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Sep 25, 2026, 12:24 PM UTC258743 bytes within scanner limit
Basis: harmless scanner · Sep 25, 2026, 12:24 PM UTCNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Sep 25, 2026, 12:24 PM UTCChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTCConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTCScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 25, 2026, 12:24 PM UTCNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Sep 25, 2026, 12:24 PM UTCSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTCHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Sep 25, 2026, 12:24 PM UTCScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTCRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Sep 25, 2026, 12:24 PM UTC1 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Sep 25, 2026, 12:24 PM UTCScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Sep 25, 2026, 12:24 PM UTC2 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Sep 25, 2026, 12:24 PM UTCsecurity:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"420650 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
description: Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re… → Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re…
Evidence: clock-guarded source update
security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"420650 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}
Evidence: Repeated harmless observation changed the modeled property
content_type → text/html; charset=utf-8
Evidence: harmless unauthenticated HTTP observation
tls_state: not-tested → tested-pass
Evidence: harmless unauthenticated HTTP observation
security:bounded_response: {"state":"tested-pass","evidence":"389177 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"389177 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
description: Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re… → Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp. Re…
Evidence: clock-guarded source update
security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"387972 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:openapi_parse: {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"} → {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless …
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"387972 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:openapi_parse: {"state":"tested-fail","evidence":"Response was JSON but not a bounded supported OpenAPI 3 document","basis":"harmless … → {"state":"tested-pass","evidence":"7 payment offer(s) accepted","basis":"harmless discovery response"}
Evidence: Repeated harmless observation changed the modeled property
security:bounded_response: {"state":"tested-pass","evidence":"845 bytes within scanner limit","basis":"harmless scanner"} → {"state":"tested-pass","evidence":"1434 bytes within scanner limit","basis":"harmless scanner"}
Evidence: Repeated harmless observation changed the modeled property
security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402","basis":"unauthenticated HTTP response"} → {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat…
Evidence: Repeated harmless observation changed the modeled property
security:challenge_parse: {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402","basis":"unauthenticated HTTP response"} → {"state":"tested-pass","evidence":"1 Payment challenge(s) observed on HTTP 402; all required fields decoded and validat…
Evidence: Repeated harmless observation changed the modeled property