Review a copied HTTP request, cURL command, and response headers for common credential, transport, CORS, cookie, cache, and exposure mistakes.
The checker evaluates only visible copied text and rules that are safe to assess locally. It cannot discover authorization flaws, rate limits, server behavior, or vulnerabilities in a live API.