Diagnostics for privileged WebView content handling and JavaScript bridge exposure.
Status: Pending checks
Environment
Timestamp
Loading…
Current Origin
Loading…
Current Hostname
Loading…
User Agent
Loading…
Automated checks have not run yet. Use the diagnostic button to evaluate whether the current origin was treated as trusted content.
The verification flow is intentionally manual. Impact demonstration buttons remain separate from the detection step.
Bridge Summary
Check
Result
Android object present
Pending
navigateNativeDeepLink()
Pending
Origin treated as trusted
Pending
Security boundary
Pending
Diagnostic Output
Impact Validation
These actions are manual and only used to confirm the effect of bridge exposure. Route strings below are verified against the app's actual deep-link router (qc4.java) rather than guessed.
A successful invocation may navigate away from this page, which is expected during impact validation. Note: reaching these screens does not itself perform the sensitive action (e.g. "deleteaccount" opens a confirmation screen, it does not delete the account) — that still requires an explicit in-app confirmation step per source review.