{"success":true,"data":{"id":"href-open-redirect","label":"Body link routes through a known open-redirect endpoint (google.com/url, l.facebook.com/l.php, etc.) — visible URL trustworthy, destination is not","description":"A body link routes through a known open-redirect endpoint on a trusted host. Phishing kits chain through `google.com/url?q=...`, `l.facebook.com/l.php?u=...`, `l.linkedin.com/?url=...`, `t.umblr.com/redirect?z=...`, and `youtube.com/redirect?q=...` so the visible URL the user hovers over shows google.com / facebook.com / linkedin.com — but the actual landing page is the attacker-controlled site in the query parameter. Mail filters and the user's own URL hover both show the trusted host; only inspecting the query string reveals the destination. The detection is allowlist-based — only the small set of major redirector endpoints whose abuse has been documented in public phishing reports — to avoid over-firing on legitimate Google search results and newsletter tracking wrappers. Weighted at +3, pairs with other phishing signals (display-name-spoof, urgency-bait) without solo-deciding because the redirector hosts themselves send legitimate click-through notifications.","tier":"danger","category":"other","isThin":false}}