Revisa una solicitud HTTP o cURL copiada y sus cabeceras de respuesta para detectar secretos en URL, HTTP sin cifrar, CORS inseguro, cookies débiles y caché inadecuada. No contacta el destino.
The checker evaluates only visible copied text and rules that are safe to assess locally. It cannot discover authorization flaws, rate limits, server behavior, or vulnerabilities in a live API.