ua-tracer
by Paul Kinlan
trace HR8kWKlJ
what does a user agent actually fetch, follow & run?
Trace HR8kWKlJ
First seen: 2026-09-11 23:15:42.276 UTC
User-Agent: Timpibot/0.9 (+http://www.timpi.io) Timpi-DomainCheck/1.0
Bot verification: Not a known bot (no IP-range check applies).
What this user agent did
Directly-referenced assets:
✗ fetched CSS
✗ fetched JS
✗ fetched image
✗ fetched font (HTML)
Document-level link hints:
✗ fetched favicon
✗ fetched apple-touch-icon
✗ fetched web manifest
✗ fetched preload
✗ fetched prefetch
Second-level follows (proves it parsed the linking file):
✗ followed CSS background-image
✗ followed CSS @font-face
✗ followed manifest icon
✗ followed CSS @import
Frames (does it descend into iframes?):
✗ fetched iframe document
✗ descended into iframe (loaded inner image)
Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):
✗ sent a CSP/Reporting report (any path)
✗ delivered via report-uri/Report-To header (no JS)
✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)
Social embed (Open Graph / Twitter card images):
✗ fetched og:image
✗ fetched twitter:image
JavaScript execution:
✗ EXECUTED classic JS
✗ EXECUTED ES module
✗ posted client timing
Server-side request waterfall
Every request the server received for this trace, in receive order. +ms is the delta from the
homepage request.
| Received | Δ | Kind | Method | User-Agent |
|---|---|---|---|---|
| 2026-09-11 23:15:42.276 UTC | +0 ms | homepage | HEAD | Timpibot/0.9 (+http://www.timpi.io) Timpi-DomainCheck/1.0 |
request headers (8){
"accept": "text/html",
"host": "uatracer.com",
"traceparent": "00-ab0cf838db19dd077926db50d218e50f-b3bc6528568cd0b1-01",
"tracestate": "",
"user-agent": "Timpibot/0.9 (+http://www.timpi.io) Timpi-DomainCheck/1.0",
"via": "HTTP/1.1 ord.vultr.prod.deno-cluster.net",
"x-deno-userspace-traceparent": "00-ab0cf838db19dd077926db50d218e50f-d0098c8bba7a2b6a-01",
"x-deno-userspace-tracestate": ""
}
|
||||