Page and scripts
Material sent to a public visitor
Reads the submitted public HTML and metadata, then analyses up to eight JavaScript assets declared by the page and served from the same origin. It looks for known secret patterns and static client side risks without entering a private repository or logged in workflow.