Payment routes and gateway calls use HTTPS only: no plaintext URL, no disabled certificate verification, and plain-HTTP requests to the deployed payment paths are redirected, never answered with content.
Inputs
Non-test code files whose path names the payment flow or that reference a gateway, plus configuration and infrastructure files (reverse proxy, platform, IaC). When the repository declares a deployed origin and the engine provides its outbound helper, plain-HTTP requests are sent to the root and to at most five payment paths found in the code. Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed.
Decision rule
Not applicable when no payment file exists. FAIL when a payment file contains an http:// URL to a non-local host or disables TLS certificate verification, or when the deployed origin answers a plain-HTTP payment path with a 2xx. PASS only with evidence: no violation AND (the plain-HTTP probes were redirected to https OR the checkout declares HTTPS enforcement: HSTS or forced redirect in the application, SECURE_SSL_REDIRECT, Talisman, HTTPSRedirectMiddleware, URL::forceScheme, a proxy 301 to https or TLS listener, CloudFront/ALB/Ingress redirect policies, or a platform that terminates TLS). Payment files without a violation and without either evidence are not applicable, never a PASS.
Type
deterministic
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
const PLAINTEXT_URL = /\bhttp:\/\/(?!(?:localhost|127\.0\.0\.1|\$\{|\{|www\.w3\.org|schema\.org))([A-Za-z0-9.-]+)/g; // in a payment file -> FAIL