Submission is denied by default.
A form monitor can create side effects. The product therefore treats every public target as observe-only until control is verified.
Target protection
The scanner accepts public HTTP and HTTPS pages only. It rejects credentials in URLs, local and private networks, nonstandard ports, automatic redirects, non-HTML responses and oversized pages.
Permission before submission
Production synthetic submission requires a short-lived signed token bound to one origin, path and run. The local build permits only three exact test fixtures.
One submission
Each run clicks Submit once. There is no automatic submission retry. This limits duplicate records, notifications and integrations.
CAPTCHA
The worker does not solve CAPTCHA. When reCAPTCHA, hCaptcha or Turnstile is detected, the run stops and reports blocked, not broken.
Excluded forms
Payments, accounts, passwords, uploads, bookings, legal consent and sensitive medical, employment or financial forms are outside the first release.
Secrets
Connection and payment secrets belong in environment variables, never source code or the monitoring database. The WordPress companion stores only the site connection secret needed to verify signed tests.