Authorization

Only run Wasit against a service you own, or one whose operator has given you explicit written permission to test.

This is an operating policy, binding on the maintainer and on every user of the tool. It is not a feature of the software, and it cannot be: no tool can determine from a URL alone who owns the service behind it. The software will not stop you from pointing it somewhere you should not. You are responsible for where you point it.

The tool does enforce one narrower guard, described under Destructive checks below, but that guard is about preventing an irreversible action taken by mistake — not about establishing that you were authorised in the first place.