Service record

DripStack

https://dripstack.xyz/
activewebdata

MPP-enabled content retrieval from Substack publications.

Implementation fingerprint
unknown no confident attribution
Fingerprint evidence
No implementation-specific public signal observed.
First seen
Aug 25, 2026, 6:43 PM UTC
Last seen
Oct 9, 2026, 12:36 PM UTC
Origin
https://dripstack.xyz
Tags
substackblogpublicationpostdataquery

Payment surface

21 MPP endpoints

This count includes endpoints established by catalog, OpenAPI, or valid runtime 402 evidence. It does not count every URL the harmless scanner attempted.

JSON record →
GET
https://dripstack.xyz/api/v1/companies
Look up a company profile by ticker, domain, qid, CIK, or name.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 31, 12:22 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/companies/%7BcompanyId%7D
Get one company profile by id.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/entities/search
Find articles that mention an entity or are linked to a stock pick.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 30, 12:21 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/me
Auth introspection for the current API key or OAuth token.
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 30, 12:23 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/me/credits
Purchased credit balance and top-up URLs.
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 31, 12:25 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/me/credits/activity
Cursor-paginated credit ledger activity.
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 31, 12:18 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/me/unlocks
Cursor-paginated posts unlocked for lifetime access.
Status: 401TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 30, 12:22 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/podcasts
List curated podcasts.
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 29, 12:20 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/podcasts/%7BpublicationSlug%7D
Get one podcast with recent episodes.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/posts/top-selling
List the most purchased posts.
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 29, 12:21 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications
List publications (free)
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 28, 06:20 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications/%7BpublicationSlug%7D
Get one publication with recent posts.
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications/%7BpublicationSlug%7D/%7BpostSlug%7D
Get article, podcast, or book chapter content (paid).
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
x402chargeopenapi1000000 USDC
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
eip155:8453
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapi1000000 USDC
Recipient
2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi1000000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
stripechargeopenapi100 usd
Recipient
profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
POST
https://dripstack.xyz/api/v1/publications/%7BpublicationSlug%7D/%7BpostSlug%7D
Access post with credits (paid, same as GET).
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
x402chargeopenapi1000000 USDC
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
eip155:8453
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapi1000000 USDC
Recipient
2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi1000000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
stripechargeopenapi100 usd
Recipient
profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications/:publicationSlug
Get list of posts for a publication (free)
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 28, 06:21 PM UTC
No normalized payment offer observed for this endpoint.
GET
https://dripstack.xyz/api/v1/publications/:publicationSlug/:postSlug
Get post content
Status: 404TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 28, 06:22 PM UTC
tempochargecatalogamount unknown 0x20c000000000000000000000b9537d11c60e8b50
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · dynamic
true
Session · amountHint
$0.05-$10
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications/search
Search curated publications, newsletters, podcasts, and authors.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 30, 06:20 AM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/publications/top-selling
List the highest-earning publications.
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 29, 12:20 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/search
Search premium financial newsletter and podcast posts by topic.
Status: 400TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 29, 06:23 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/stock-picks
List stock-picker calls for one day (paid).
Status: not probedTLS: not-testedRedirects: unknownChallenge: not observedLast probe: unknown time
x402chargeopenapi500000 USDC
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
eip155:8453
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
x402chargeopenapi500000 USDC
Recipient
2cCuDjNEuA7QFgBiS8rYcWrxJxeYGJFGHvXaaCXBqmHF
Chain
not observed
Unit type
not observed
Session · scheme
exact
Session · network
solana:5eykt4UsFv8P8NJdTREpY1vzqKqZKvdp
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
tempochargeopenapi500000 0x20C000000000000000000000b9537d11c60E8b50
Recipient
0xBF22b6DdB5A08c823856A779f1004eEa60C5aB92
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
stripechargeopenapi50 usd
Recipient
profile_61Umz1FUfXxChDA5oA6Umz1EM7SQ1AjJpNQxiSGWWUSe
Chain
not observed
Unit type
not observed
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.
GET
https://dripstack.xyz/api/v1/stock-picks/quote
Quote the stock-picks bundle price for one day (free).
Status: 200TLS: tested-passRedirects: 0Challenge: not observedLast probe: Aug 29, 12:19 PM UTC
unknownchargeopenapiamount unknown currency unknown
Recipient
not observed
Chain
not observed
Unit type
not observed
Session · authMode
none
Economic exposure: unknown — the public observation does not contain enough session or authorization inputs to calculate it.

Probe coverage

162 harmless observations

These are bounded unauthenticated requests and scanner-policy stops. A response without MPP evidence remains a discovery result, not a security failure.

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 9, 2026, 12:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 9, 2026, 6:32 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 9, 2026, 12:37 AM UTC

GET https://dripstack.xyz/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/openapi.json was recorded but not followed

Oct 9, 2026, 12:19 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 8, 2026, 6:39 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 8, 2026, 12:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 8, 2026, 6:36 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 8, 2026, 12:35 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 7, 2026, 6:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 7, 2026, 12:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 7, 2026, 6:38 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 7, 2026, 12:41 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 6, 2026, 6:39 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 6, 2026, 12:40 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 6, 2026, 6:32 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 6, 2026, 12:37 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 5, 2026, 6:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 5, 2026, 12:35 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 5, 2026, 6:34 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 5, 2026, 12:34 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 4, 2026, 6:33 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 4, 2026, 12:37 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 4, 2026, 6:35 AM UTC

GET https://dripstack.xyz/.well-known/api-catalog

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/.well-known/api-catalog was recorded but not followed

Oct 4, 2026, 6:22 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 4, 2026, 12:36 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 3, 2026, 6:35 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 3, 2026, 12:40 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 3, 2026, 6:32 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 3, 2026, 12:38 AM UTC

GET https://dripstack.xyz/api/v1/publications/:publicationSlug/:postSlug

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug/:postSlug was recorded but not followed

Oct 3, 2026, 12:31 AM UTC

GET https://dripstack.xyz/api/v1/publications/:publicationSlug

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug was recorded but not followed

Oct 3, 2026, 12:30 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 2, 2026, 6:36 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 2, 2026, 12:46 PM UTC

GET https://dripstack.xyz/api/v1/publications

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/api/v1/publications was recorded but not followed

Oct 2, 2026, 12:21 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 2, 2026, 6:34 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 2, 2026, 12:35 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 1, 2026, 6:33 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 1, 2026, 12:38 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 1, 2026, 6:32 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Oct 1, 2026, 12:36 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 30, 2026, 6:33 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 30, 2026, 12:33 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 30, 2026, 6:36 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 30, 2026, 12:33 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 29, 2026, 6:33 PM UTC

GET https://dripstack.xyz/openapi.json

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/openapi.json was recorded but not followed

Sep 29, 2026, 6:20 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 29, 2026, 12:32 PM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 29, 2026, 6:32 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 29, 2026, 12:33 AM UTC

GET https://dripstack.xyz/

scanner stopped: cross-host-redirect

Cross-host redirect to https://dripstack.com/ was recorded but not followed

Sep 28, 2026, 6:36 PM UTC
Showing the latest 50 of 162 observations.

Evidence model

Security properties

Every result names its evidence state. Unknown and not tested never mean secure.

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not followed

Basis: scanner policy decision · Oct 9, 2026, 12:36 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug/:postSlug was recorded but not followed

Basis: scanner policy decision · Oct 3, 2026, 12:31 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/:publicationSlug was recorded but not followed

Basis: scanner policy decision · Oct 3, 2026, 12:30 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications was recorded but not followed

Basis: scanner policy decision · Oct 2, 2026, 12:21 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/companies was recorded but not followed

Basis: scanner policy decision · Sep 9, 2026, 12:24 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/credits/activity was recorded but not followed

Basis: scanner policy decision · Sep 8, 2026, 6:22 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/credits was recorded but not followed

Basis: scanner policy decision · Sep 8, 2026, 12:23 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me was recorded but not followed

Basis: scanner policy decision · Sep 7, 2026, 6:25 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/search was recorded but not followed

Basis: scanner policy decision · Sep 7, 2026, 6:24 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/me/unlocks was recorded but not followed

Basis: scanner policy decision · Sep 7, 2026, 6:22 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/entities/search was recorded but not followed

Basis: scanner policy decision · Sep 7, 2026, 6:21 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/search was recorded but not followed

Basis: scanner policy decision · Sep 7, 2026, 12:22 AM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/posts/top-selling was recorded but not followed

Basis: scanner policy decision · Sep 6, 2026, 12:21 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/publications/top-selling was recorded but not followed

Basis: scanner policy decision · Sep 6, 2026, 12:20 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/podcasts was recorded but not followed

Basis: scanner policy decision · Sep 6, 2026, 12:20 PM UTC

probe_safety

Observed

cross-host-redirect: Cross-host redirect to https://dripstack.com/api/v1/stock-picks/quote was recorded but not followed

Basis: scanner policy decision · Sep 6, 2026, 12:19 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:22 PM UTC

bounded_response

Tested — pass

133 bytes within scanner limit

Basis: harmless scanner · Aug 31, 2026, 12:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 31, 2026, 12:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 31, 2026, 12:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 31, 2026, 12:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 31, 2026, 12:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 31, 2026, 12:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:18 PM UTC

bounded_response

Tested — pass

120 bytes within scanner limit

Basis: harmless scanner · Aug 31, 2026, 12:18 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 31, 2026, 12:18 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:18 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 31, 2026, 12:18 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 31, 2026, 12:18 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 31, 2026, 12:18 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 31, 2026, 12:18 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:18 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:18 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 31, 2026, 12:25 AM UTC

bounded_response

Tested — pass

120 bytes within scanner limit

Basis: harmless scanner · Aug 31, 2026, 12:25 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 31, 2026, 12:25 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:25 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 31, 2026, 12:25 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 31, 2026, 12:25 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 31, 2026, 12:25 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 31, 2026, 12:25 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 31, 2026, 12:25 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 31, 2026, 12:25 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:23 PM UTC

bounded_response

Tested — pass

120 bytes within scanner limit

Basis: harmless scanner · Aug 30, 2026, 12:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 30, 2026, 12:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 30, 2026, 12:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 30, 2026, 12:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 30, 2026, 12:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 30, 2026, 12:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 6:20 AM UTC

bounded_response

Tested — pass

142 bytes within scanner limit

Basis: harmless scanner · Aug 30, 2026, 6:20 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 30, 2026, 6:20 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 6:20 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 30, 2026, 6:20 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 30, 2026, 6:20 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 30, 2026, 6:20 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 30, 2026, 6:20 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 6:20 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 6:20 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:22 AM UTC

bounded_response

Tested — pass

120 bytes within scanner limit

Basis: harmless scanner · Aug 30, 2026, 12:22 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 30, 2026, 12:22 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:22 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 30, 2026, 12:22 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 30, 2026, 12:22 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 30, 2026, 12:22 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 30, 2026, 12:22 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:22 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:22 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 30, 2026, 12:21 AM UTC

bounded_response

Tested — pass

156 bytes within scanner limit

Basis: harmless scanner · Aug 30, 2026, 12:21 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 30, 2026, 12:21 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:21 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 30, 2026, 12:21 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 30, 2026, 12:21 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 30, 2026, 12:21 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 30, 2026, 12:21 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 30, 2026, 12:21 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 30, 2026, 12:21 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 6:23 PM UTC

bounded_response

Tested — pass

130 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 6:23 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 6:23 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 6:23 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 6:23 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 6:23 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 6:23 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 6:23 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 6:23 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 6:23 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:21 PM UTC

bounded_response

Tested — pass

3189 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 12:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 12:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 12:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 12:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 12:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 12:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:20 PM UTC

bounded_response

Tested — pass

3596 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 12:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 12:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 12:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:20 PM UTC

bounded_response

Tested — pass

6157 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 12:20 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 12:20 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 12:20 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 12:20 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 12:20 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:20 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:20 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:19 PM UTC

bounded_response

Tested — pass

395 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 12:19 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 12:19 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:19 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 12:19 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 12:19 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 12:19 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 12:19 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:19 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:19 PM UTC

api_catalog_parse

Observed

API catalog source returned HTTP 404; prior advertised links were withdrawn

Basis: RFC 9727 discovery response · Aug 29, 2026, 12:23 AM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 29, 2026, 12:23 AM UTC

bounded_response

Tested — pass

115023 bytes within scanner limit

Basis: harmless scanner · Aug 29, 2026, 12:23 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 29, 2026, 12:23 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:23 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 29, 2026, 12:23 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 29, 2026, 12:23 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 29, 2026, 12:23 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 29, 2026, 12:23 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 29, 2026, 12:23 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 29, 2026, 12:23 AM UTC

openapi_parse

Tested — pass

28 payment offer(s) accepted

Basis: harmless discovery response · Aug 28, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:22 PM UTC

bounded_response

Tested — pass

27 bytes within scanner limit

Basis: harmless scanner · Aug 28, 2026, 6:22 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 28, 2026, 6:22 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:22 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 28, 2026, 6:22 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 28, 2026, 6:22 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 28, 2026, 6:22 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 28, 2026, 6:22 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:22 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:22 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:21 PM UTC

bounded_response

Tested — pass

34 bytes within scanner limit

Basis: harmless scanner · Aug 28, 2026, 6:21 PM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 28, 2026, 6:21 PM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:21 PM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 28, 2026, 6:21 PM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 28, 2026, 6:21 PM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 28, 2026, 6:21 PM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 28, 2026, 6:21 PM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:21 PM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:21 PM UTC

authorization_delivery_settlement

Not tested

Requires paid or state-changing behavior outside scanner scope

Basis: Tempo Aug 24 research class · Prior art: https://github.com/wevm/mppx/pull/510#discussion_r3377899233 · Aug 28, 2026, 6:20 AM UTC

bounded_response

Tested — pass

17824 bytes within scanner limit

Basis: harmless scanner · Aug 28, 2026, 6:20 AM UTC

challenge_parse

Unknown

No MPP Payment challenge observed

Basis: unauthenticated HTTP response · Aug 28, 2026, 6:20 AM UTC

channel_lifecycle_binding

Not tested

Channel and settlement lifecycle require credentials or payments

Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTC

concurrency_single_winner

Not tested

Concurrency and paid state changes are prohibited

Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTC

credential_replay

Not tested

Scanner never sends credentials or payments

Basis: methodology · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:20 AM UTC

economic_exposure_metadata

Unknown

No current Payment challenge exposes session or authorization inputs

Basis: observable challenge values only · Aug 28, 2026, 6:20 AM UTC

fee_payer_cosigner_binding

Not tested

Signature and fee-payer relationships are not observable unauthenticated

Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTC

https_transport

Tested — pass

HTTPS fetch completed with platform certificate validation

Basis: platform TLS validation · Aug 28, 2026, 6:20 AM UTC

method_fallback_policy

Not tested

Scanner does not select, downgrade, or execute payment methods

Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTC

price_debit_consistency

Not tested

Requires a completed paid interaction outside scanner scope

Basis: public economic-security prior art · Aug 28, 2026, 6:20 AM UTC

redirect_policy

Tested — pass

0 redirects; every hop passed URL and DNS validation

Basis: harmless scanner · Aug 28, 2026, 6:20 AM UTC

replay_idempotency_scope

Not tested

Scanner never replays signed credentials

Basis: public advisory and protocol prior art · Prior art: https://github.com/advisories/GHSA-fxc9-7j2w-vx54 · Aug 28, 2026, 6:20 AM UTC

ssrf_target_validation

Tested — pass

1 hop(s) resolved twice to stable public addresses

Basis: scanner URL, DNS and redirect policy · Aug 28, 2026, 6:20 AM UTC

probe_safety

Observed

Response exceeds 262144 bytes

Basis: scanner policy decision · Aug 25, 2026, 7:20 PM UTC

History

Service changes

Showing the latest 50 of 230 changes. Continue in the changes API view.

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/.well-known/api-catal…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco…

Evidence: Repeated harmless observation changed the modeled property

— security-property-changed

security:probe_safety: {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/openapi.json was reco… → {"state":"observed","evidence":"cross-host-redirect: Cross-host redirect to https://dripstack.com/ was recorded but not…

Evidence: Repeated harmless observation changed the modeled property