This project is an educational and defensive scanner. Results are heuristics and must be manually validated; the tool must not be treated as proof of exploitability.
Run scans only against systems you own or are explicitly authorized to test. Do not use this project for unauthorized reconnaissance, denial of service, credential attacks, or data extraction. Prefer local fixtures and intentionally vulnerable training applications when developing or testing changes.
Please do not disclose exploitable details in a public issue. Use GitHub's Private vulnerability reporting feature for this repository, and include the affected commit or version, a minimal harmless reproduction, impact, and suggested remediation.
Never commit credentials, tokens, private URLs, personal data, or scan output containing sensitive information. Redact target details from issues and pull requests.