API Security
Review methods advertised through Allow and CORS metadata without sending destructive requests.
API inspection is limited to saved targets that you have explicitly authorized and that are currently active.