30 checks in Security & Privacy. Automated Its subsection has a live automated checker in the engine.
| ID | Check | Passes when |
|---|---|---|
| 7.9.01 | Validate all incoming parameters strictly whitelisted | Whitelisted |
| 7.9.02 | Detect unvalidated free-form parameters | None |
| 7.9.03 | Validate numeric parameters type-enforced | Enforced |
| 7.9.04 | Validate boolean parameters restricted to true/false | Restricted |
| 7.9.05 | Validate enum parameters validated against allowed list | Validated |
| 7.9.06 | Detect abnormal parameter combinations (anomaly detection) | None |
| 7.9.07 | Detect uncontrolled param fan-out (too many params) | Controlled |
| 7.9.08 | Validate short parameter length limits | Limited |
| 7.9.09 | Validate high-risk params removed (callback=, redirect=, proxy=) | Removed |
| 7.9.10 | Compute Parameter Safety Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.9.11 | Validate all parameters HTML-escaped server-side | Escaped |
| 7.9.12 | Validate JS-escaped for front-end usage | Escaped |
| 7.9.13 | Validate URL-encoding normalized | Normalized |
| 7.9.14 | Detect double-encoding attempts | None |
| 7.9.15 | Detect encoding smuggling (Unicode confusables) | None |
| 7.9.16 | Validate special characters filtered (< > ' " ; { }) | Filtered |
| 7.9.17 | Validate normalization prevents path traversal (../) | Prevented |
| 7.9.18 | Detect SQL injection patterns in params | None |
| 7.9.19 | Detect XSS payload patterns | None |
| 7.9.20 | Compute Sanitization Integrity Score | Finalized |
| ID | Check | Passes when |
|---|---|---|
| 7.9.21 | Validate parameter ordering canonicalized | Canonical |
| 7.9.22 | Validate empty parameters removed | Removed |
| 7.9.23 | Validate tracking params stripped from canonical URLs | Stripped |
| 7.9.24 | Detect param-based duplication threats | None |
| 7.9.25 | Validate no param creates infinite crawl spaces | None |
| 7.9.26 | Validate canonical tag ignores non-essential params | Ignored |
| 7.9.27 | Validate sitemaps exclude non-canonical param variants | Excluded |
| 7.9.28 | Detect param collisions across templates | None |
| 7.9.29 | Validate search/filter params URL-encoded safely | Safe |
| 7.9.30 | Compute URL Parameter Sanitization Master Score | Finalized |
← 7.8 Cache Poisoning Defense7.10 Advanced Security Trust Signals →
A Deep Audit scores every check here that applies to your page, then an AI pass of up to 150 checks. Included on Pro and Ultra, or $9 for one audit.
See plansMachine-readable: catalog totals and the full catalog as JSON (IDs, section, weight, status).