- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
MPP-enabled content retrieval from Substack publications.
- Implementation fingerprint
- unknown no confident attribution
- Fingerprint evidence
- No implementation-specific public signal observed.
- First seen
- Aug 25, 2026, 6:43 PM UTC
- Last seen
- Oct 9, 2026, 12:36 PM UTC
- Origin
- https://dripstack.xyz
- Tags
- substackblogpublicationpostdataquery
Payment surface
21 MPP endpoints
This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- eip155:8453
- Recipient
- 2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Recipient
- profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
- Chain
- not observed
- Unit type
- not observed
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- eip155:8453
- Recipient
- 2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Recipient
- profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · dynamic
- true
- Session · amountHint
- $0.05-$10
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- eip155:8453
- Recipient
- 2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
- Chain
- not observed
- Unit type
- not observed
- Session · scheme
- exact
- Session · network
- solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
- Recipient
- 0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
- Chain
- not observed
- Unit type
- not observed
- Recipient
- profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
- Chain
- not observed
- Unit type
- not observed
- Recipient
- not observed
- Chain
- not observed
- Unit type
- not observed
- Session · authMode
- none
Probe coverage
162 harmless observations
These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.
GET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 9, 2026, 12:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 9, 2026, 6:32 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 9, 2026, 12:37 AM UTCGET https://dripstack.xyz/openapi.json
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/openapi.json was recorded but not followed
Oct 9, 2026, 12:19 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 8, 2026, 6:39 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 8, 2026, 12:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 8, 2026, 6:36 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 8, 2026, 12:35 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 7, 2026, 6:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 7, 2026, 12:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 7, 2026, 6:38 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 7, 2026, 12:41 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 6, 2026, 6:39 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 6, 2026, 12:40 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 6, 2026, 6:32 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 6, 2026, 12:37 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 5, 2026, 6:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 5, 2026, 12:35 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 5, 2026, 6:34 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 5, 2026, 12:34 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 4, 2026, 6:33 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 4, 2026, 12:37 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 4, 2026, 6:35 AM UTCGET https://dripstack.xyz/.well-known/api-catalog
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/.well-known/api-catalog was recorded but not followed
Oct 4, 2026, 6:22 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 4, 2026, 12:36 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 3, 2026, 6:35 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 3, 2026, 12:40 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 3, 2026, 6:32 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 3, 2026, 12:38 AM UTCGET https://dripstack.xyz/api/v1/publications/:publicationSlug/:postSlug
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug/:postSlug was recorded but not followed
Oct 3, 2026, 12:31 AM UTCGET https://dripstack.xyz/api/v1/publications/:publicationSlug
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug was recorded but not followed
Oct 3, 2026, 12:30 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 2, 2026, 6:36 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 2, 2026, 12:46 PM UTCGET https://dripstack.xyz/api/v1/publications
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/api/v1/publications was recorded but not followed
Oct 2, 2026, 12:21 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 2, 2026, 6:34 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 2, 2026, 12:35 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 1, 2026, 6:33 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 1, 2026, 12:38 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 1, 2026, 6:32 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Oct 1, 2026, 12:36 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 30, 2026, 6:33 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 30, 2026, 12:33 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 30, 2026, 6:36 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 30, 2026, 12:33 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 29, 2026, 6:33 PM UTCGET https://dripstack.xyz/openapi.json
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/openapi.json was recorded but not followed
Sep 29, 2026, 6:20 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 29, 2026, 12:32 PM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 29, 2026, 6:32 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 29, 2026, 12:33 AM UTCGET https://dripstack.xyz/
scanner stopped: cross-host-redirectCross-host redirect to https://dripstack.com/ was recorded but not followed
Sep 28, 2026, 6:36 PM UTCEvidence model
Security properties
Every result names its evidence state. Unknown and not tested never mean secure.
probe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not followed
Basis: scanner policy decision · Oct 9, 2026, 12:36 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug/:postSlug was recorded but not followed
Basis: scanner policy decision · Oct 3, 2026, 12:31 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug was recorded but not followed
Basis: scanner policy decision · Oct 3, 2026, 12:30 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications was recorded but not followed
Basis: scanner policy decision · Oct 2, 2026, 12:21 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/companies was recorded but not followed
Basis: scanner policy decision · Sep 9, 2026, 12:24 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/credits/activity was recorded but not followed
Basis: scanner policy decision · Sep 8, 2026, 6:22 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/credits was recorded but not followed
Basis: scanner policy decision · Sep 8, 2026, 12:23 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me was recorded but not followed
Basis: scanner policy decision · Sep 7, 2026, 6:25 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/search was recorded but not followed
Basis: scanner policy decision · Sep 7, 2026, 6:24 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/unlocks was recorded but not followed
Basis: scanner policy decision · Sep 7, 2026, 6:22 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/entities/search was recorded but not followed
Basis: scanner policy decision · Sep 7, 2026, 6:21 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/search was recorded but not followed
Basis: scanner policy decision · Sep 7, 2026, 12:22 AM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/posts/top-selling was recorded but not followed
Basis: scanner policy decision · Sep 6, 2026, 12:21 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/top-selling was recorded but not followed
Basis: scanner policy decision · Sep 6, 2026, 12:20 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/podcasts was recorded but not followed
Basis: scanner policy decision · Sep 6, 2026, 12:20 PM UTCprobe_safety
Observedcross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/stock-picks/quote was recorded but not followed
Basis: scanner policy decision · Sep 6, 2026, 12:19 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:22 PM UTCbounded_response
Tested — pass133 bytes within scanner limit
Basis: harmless scanner · Aug 31, 2026, 12:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 31, 2026, 12:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 31, 2026, 12:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 31, 2026, 12:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 31, 2026, 12:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:18 PM UTCbounded_response
Tested — pass120 bytes within scanner limit
Basis: harmless scanner · Aug 31, 2026, 12:18 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 31, 2026, 12:18 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:18 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 31, 2026, 12:18 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 31, 2026, 12:18 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 31, 2026, 12:18 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:18 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:18 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:25 AM UTCbounded_response
Tested — pass120 bytes within scanner limit
Basis: harmless scanner · Aug 31, 2026, 12:25 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 31, 2026, 12:25 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:25 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 31, 2026, 12:25 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 31, 2026, 12:25 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 31, 2026, 12:25 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:25 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:25 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:23 PM UTCbounded_response
Tested — pass120 bytes within scanner limit
Basis: harmless scanner · Aug 30, 2026, 12:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 30, 2026, 12:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 30, 2026, 12:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 30, 2026, 12:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 30, 2026, 12:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 6:20 AM UTCbounded_response
Tested — pass142 bytes within scanner limit
Basis: harmless scanner · Aug 30, 2026, 6:20 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 30, 2026, 6:20 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 6:20 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 30, 2026, 6:20 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 30, 2026, 6:20 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 30, 2026, 6:20 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 6:20 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 6:20 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:22 AM UTCbounded_response
Tested — pass120 bytes within scanner limit
Basis: harmless scanner · Aug 30, 2026, 12:22 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 30, 2026, 12:22 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:22 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 30, 2026, 12:22 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 30, 2026, 12:22 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 30, 2026, 12:22 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:22 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:22 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:21 AM UTCbounded_response
Tested — pass156 bytes within scanner limit
Basis: harmless scanner · Aug 30, 2026, 12:21 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 30, 2026, 12:21 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:21 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 30, 2026, 12:21 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 30, 2026, 12:21 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 30, 2026, 12:21 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:21 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:21 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 6:23 PM UTCbounded_response
Tested — pass130 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 6:23 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 6:23 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 6:23 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 6:23 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 6:23 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 6:23 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 6:23 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 6:23 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:21 PM UTCbounded_response
Tested — pass3189 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 12:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 12:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 12:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 12:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 12:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:20 PM UTCbounded_response
Tested — pass3596 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 12:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 12:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 12:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:20 PM UTCbounded_response
Tested — pass6157 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 12:20 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 12:20 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 12:20 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:20 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:19 PM UTCbounded_response
Tested — pass395 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 12:19 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 12:19 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:19 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 12:19 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 12:19 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 12:19 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:19 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:19 PM UTCapi_catalog_parse
ObservedAPI catalog source returned HTTP 404; prior advertised links were withdrawn
Basis: RFC 9727 discovery response · Aug 29, 2026, 12:23 AM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:23 AM UTCbounded_response
Tested — pass115023 bytes within scanner limit
Basis: harmless scanner · Aug 29, 2026, 12:23 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 29, 2026, 12:23 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:23 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 29, 2026, 12:23 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 29, 2026, 12:23 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 29, 2026, 12:23 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:23 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:23 AM UTCopenapi_parse
Tested — pass28 payment offer(s) accepted
Basis: harmless discovery response · Aug 28, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:22 PM UTCbounded_response
Tested — pass27 bytes within scanner limit
Basis: harmless scanner · Aug 28, 2026, 6:22 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 28, 2026, 6:22 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:22 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 28, 2026, 6:22 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 28, 2026, 6:22 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 28, 2026, 6:22 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:22 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:22 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:21 PM UTCbounded_response
Tested — pass34 bytes within scanner limit
Basis: harmless scanner · Aug 28, 2026, 6:21 PM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 28, 2026, 6:21 PM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:21 PM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 28, 2026, 6:21 PM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 28, 2026, 6:21 PM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 28, 2026, 6:21 PM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:21 PM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:21 PM UTCauthorization_delivery_settlement
Not testedRequires paid or state-changing behavior outside scanner scope
Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:20 AM UTCbounded_response
Tested — pass17824 bytes within scanner limit
Basis: harmless scanner · Aug 28, 2026, 6:20 AM UTCchallenge_parse
UnknownNo MPP Payment challenge observed
Basis: unauthenticated HTTP response · Aug 28, 2026, 6:20 AM UTCchannel_lifecycle_binding
Not testedChannel and settlement lifecycle require credentials or payments
Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTCconcurrency_single_winner
Not testedConcurrency and paid state changes are prohibited
Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTCcredential_replay
Not testedScanner never sends credentials or payments
Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:20 AM UTCeconomic_exposure_metadata
UnknownNo current Payment challenge exposes session or authorization inputs
Basis: observable challenge values only · Aug 28, 2026, 6:20 AM UTCfee_payer_cosigner_binding
Not testedSignature and fee-payer relationships are not observable unauthenticated
Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTChttps_transport
Tested — passHTTPS fetch completed with platform certificate validation
Basis: platform TLS validation · Aug 28, 2026, 6:20 AM UTCmethod_fallback_policy
Not testedScanner does not select, downgrade, or execute payment methods
Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTCprice_debit_consistency
Not testedRequires a completed paid interaction outside scanner scope
Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTCredirect_policy
Tested — pass0 redirects; every hop passed URL and DNS validation
Basis: harmless scanner · Aug 28, 2026, 6:20 AM UTCreplay_idempotency_scope
Not testedScanner never replays signed credentials
Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:20 AM UTCssrf_target_validation
Tested — pass1 hop(s) resolved twice to stable public addresses
Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:20 AM UTCprobe_safety
ObservedResponse exceeds 262144 bytes
Basis: scanner policy decision · Aug 25, 2026, 7:20 PM UTC— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…
Evidence: Repeated harmless observation changed the modeled property
— security-property-changed
security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…
Evidence: Repeated harmless observation changed the modeled property