No URL built by the application and no query parameter read by the server carries a credential, a session identifier, a long-lived token or personal data. No AI engine is involved: the verdict is reproducible from the source alone.
Inputs
Non-test code files of the checkout (JavaScript, TypeScript, Python, PHP), analysed statically with the platform kit (tokens, function units, calls, imports). Units of analysis: string and template literals with a query string; searchParams/params.set or append('x'); new URLSearchParams({...}), qs/querystring.stringify({...}), http_build_query([...]); a params, query, qs or searchParams object handed to an HTTP client call (axios, fetch, got, ky, superagent, $http, request, api/client instances) — never a DAO query object nor a type annotation; Python url_for(..., x=), urlencode({...}), redirect; Laravel route(), url(), to_route(), action() with an array; and server-side reads: req.query.x, req.query['x'], searchParams.get('x'), request.args.get/[], request.GET, request.query_params, $request->query('x'), $_GET['x'], Hono c.req.query('x'), Koa ctx.query.x, Next router.query.x and destructured searchParams/req.query. The parameter name is the string literal or object key at the site. For a generic token parameter (token, t, key, code, ticket, hash, signature, sig) the enclosing function, the functions it calls within 2 module hops and the file path are searched for single-use or expiry vocabulary (expires, ttl, max-age, single-use, one-time, consume, used_at, invalidate, revoke, verify-email, reset, magic link, invitation, unsubscribe, confirm, nonce, activation, jwt.sign, setex, presigned). Paths listed in excludes are never analysed. Nothing of the checkout is executed.
Decision rule
A query-string construction (new URLSearchParams, qs/querystring.stringify, http_build_query, urlencode) counts only when it reaches a URL: used as the request BODY — the value of a body, data, form, form_data, payload, json, content, fields or files key, or the data argument of a .post(), .put() or .patch() client call — it is a form encoding of the body, never a query string, and it is not judged (the trace names the key or the call). Not applicable when no URL with a query string is built and no query parameter is read. FAIL (HIGH, credential-in-query) when a query parameter name denotes a credential or session identifier (session id, sid, phpsessid, access/auth/id/refresh token, API key, password, secret, client secret, JWT, bearer, OTP, PIN, private key, credentials, authorization). A personal-data name (e-mail, phone, mobile, SSN, national id, DNI/NIF/NIE, passport, tax id, VAT, IBAN, card number, PAN, CVV, date of birth, address, street, first/last/full name, surname) is MEDIUM (personal-data-in-query; blocks only in Extended suites); an address or street parameter next to wallet vocabulary (wallet, deposit, network, chain, USDT, BTC, ETH, Tron, Bitfinex, NOWPayments) is a wallet address and is not reported. A generic token parameter with single-use or expiry evidence in its function, its callees within 2 module hops, or its file path is accepted and reported LOW (single-use-token-in-query, informative); without such evidence it is MEDIUM (long-lived-token-in-query). Third-party signed-link parameters (X-Amz-*, Signature, Key-Pair-Id, Policy, Expires, X-Goog-*, Azure SAS sv/se/sp/sr/sig set, Stripe payment_intent_client_secret, Firebase oobCode) are declared not judged and never reported. PASS when every construction and read was scanned and nothing blocking was found. Not judged by this check (declared): whether an expiring token actually expires (the evidence is vocabulary in the code path, not execution) and opaque ids that identify a record without authorising access.
Type
deterministic
1.1.2: a callee whose root is a name that `Object.prototype` also carries (`build().toString()` tokenizes to the bare callee `toString`; also `constructor`, `valueOf`, `hasOwnProperty`) was looked up in the plain object that holds the imported names, so it resolved to the INHERITED FUNCTION instead of to nothing and the whole check died with "name.includes is not a function". Only a real binding counts now, and the name of a unit is always read as a string. Found on a 1 319-file checkout (2fa-available and session-expiry-rotation, 2026-09-24); the same line was in the 15 scripts that walk the call graph, so all fifteen ship the fix. (1.1.1: false positive of the attestation of platform/apps/auth (2026-09-24), fixed in the script: una construcción de query string (new URLSearchParams, qs/querystring.stringify, http_build_query, urlencode) sólo cuenta si LLEGA A UNA URL: usada como CUERPO de la petición (valor de una clave body, data, form, payload, json, content, fields o files, o argumento de datos de un .post()/.put()/.patch()) es una codificación del cuerpo, no una query string, y no se juzga. (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. Construcciones de URL y lecturas de query a nivel de token; token genérico con vocabulario de un solo uso = LOW, sin él = MEDIUM.))
// the unit is a URL construction or a query read found on the kit's tokens; the parameter name is the literal or object key at the site
const CREDENTIAL_PARAM = /^(?:session_?id|sid|phpsessid|access_?token|api_?key|auth_?token|password|secret|client_?secret|jwt|bearer|id_?token|refresh_?token|otp|pin)$/i; // -> HIGH
const PERSONAL_PARAM = /^(?:e-?mail|phone|mobile|ssn|dni|nif|passport|tax_?id|iban|card_?number|dob|birth_?date|address|first_?name|last_?name)$/i; // -> MEDIUM (address next to wallet vocabulary is not personal data)
// a generic `token` with EXPIRY_VOCAB in its function, its callees (<= 2 module hops) or its file path -> LOW informative; without it -> MEDIUM long-lived-token-in-query
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.