01
SSRF controls
Remote URL checks reject credentials, custom ports, local names, IP literals and reserved IPv4 ranges, and revalidate redirects.
Public evidence stays bounded. Sensitive text stays local. Production changes stay yours.
Remote URL checks reject credentials, custom ports, local names, IP literals and reserved IPv4 ranges, and revalidate redirects.
The secret and CSP analyzers run entirely in the browser. The UI makes this boundary visible before input.
Stripe Checkout Sessions are created server-side and paid access is verified against an allowlisted live Price.
Email security@exposureaudit.net with reproduction steps and impact. Do not access other users' data, disrupt service or use social engineering. Good-faith, bounded reports will be reviewed.