Radar validates the target, collects bounded evidence, correlates independent signals and reports both findings and analysis limits.
1. Validate the public destination
Radar accepts public HTTP and HTTPS URLs and blocks private, loopback, metadata and system network ranges. Redirect destinations are validated at each hop.
2. Collect a bounded response
Strict time, size, redirect and concurrency limits reduce abuse. Static analysis examines the response without executing scripts or opening downloads.
3. Apply explainable checks
Independent rules examine URL structure, reputation, domain and hosting context, TLS, redirects, page content, forms, scripts, clipboard behaviour and file-delivery signals. Findings retain a reason and severity.
4. Use isolated rendering selectively
Eligible scans may run in a separate credential-free browser environment. It records bounded network and behaviour evidence, may perform one controlled verification interaction and never submits forms or runs system commands.
5. Correlate without overstating
Radar combines related signals and can identify privacy-bounded shared infrastructure across eligible public reports. Correlation informs investigation but does not independently make a malicious verdict.
6. Show limits
Challenges, timeouts and incomplete coverage are labelled. A low score means strong warning signs were not observed in the available evidence; it is not a guarantee of safety.