qr-code.api.klymax402.com
https://qr-code.api.klymax402.com/mcp
83
trust
0.55
confidence
low
risk
trust-2026-08-12.2
observed 1d ago
Why this score
| oauth_metadata_present | +14 |
| tls_present_and_valid | +12 |
| reachable | +6 |
| mcp_capabilities_discoverable | +4 |
| headers.missing_hsts | -3 |
Findings (2)
| low | No Strict-Transport-Security header headers.missing_hsts @ 1.0.0 |
| info | CORS allows any origin cors.wildcard_origin @ 1.0.0 |
Evidence (7)
| Type | Observed | SHA-256 |
|---|---|---|
| dns_resolution_observation | 1d ago | 25aa8ed9421c0cca… |
| http_response_observation | 1d ago | 029da5d53445cee1… |
| availability_observation | 1d ago | 98c2937ee1300a0d… |
| tls_certificate_observation | 1d ago | c11416375d98d5db… |
| oauth_metadata_observation | 1d ago | 637c6e23cefc1065… |
| mcp_protocol_observation | 1d ago | c662ecab5e6c1be3… |
| mcp_capability_observation | 1d ago | 4b9134fc75f72e43… |
Every record is append-only and content-hashed. Corrections supersede; nothing is overwritten.
Operate this service?
Prove control of qr-code.api.klymax402.com to correct the record and request a rescan after fixing a finding. One DNS record — no account needed.