No, this URL actually gets blocked if someone other than you (or anyone else who has already used the secret URL parameter) tries to use it. Since you gave me your site's URL I did try it and immediately got an error 403 page with the stock Admin Tools message “We detected that your latest request may have been part of suspicious activity and has been blocked. If you believe you are getting this message in error please let us know through our site's contact form.”
If you use a different browser / device you have not used before with this site or, better yet, your browser's incognito / private browsing mode you will see that you get blocked just fine trying to access this URL,
What actually happened in your testing is that the "someone" who tested this URL was… you. It wasn't a random person. You had already used the secret URL parameter feature in the same browser you used for testing. Therefore, your browser now has a cookie which lets you skip this check next time you visit the site's administrator.
To use a military analogy: If you are the commander of the base the sentry at the gate will wave you through without checking your papers; they know who you are. This doesn't mean the sentry is doing something wrong. It means that if you want to test whether they stop unauthorized people from entering you should have an unauthorized person try to enter, not the commander of the base.
For more information please read https://www.akeeba.com/documentation/admin-tools-joomla/waf-configure.html#waf-configure-basic-protection under "Administrator secret URL parameter" and "Browser cookie override for the administrator secret URL parameter".
I hope this helps you understand better what is going on.
Nicholas K. Dionysopoulos
Lead Developer and Director
🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!