ua-tracer by Paul Kinlan

trace NMZdSnet

ua-tracer

what does a user agent actually fetch, follow & run?

← all traces

Trace NMZdSnet

First seen: 2026-08-09 00:22:56.534 UTC
User-Agent: rawweb-bot/1.0 (+https://rawweb.org/)
Bot verification: Not a known bot (no IP-range check applies).

What this user agent did

Directly-referenced assets:

✗ fetched CSS ✗ fetched JS ✗ fetched image ✗ fetched font (HTML)

Document-level link hints:

✗ fetched favicon ✗ fetched apple-touch-icon ✗ fetched web manifest ✗ fetched preload ✗ fetched prefetch

Second-level follows (proves it parsed the linking file):

✗ followed CSS background-image ✗ followed CSS @font-face ✗ followed manifest icon ✗ followed CSS @import

Frames (does it descend into iframes?):

✗ fetched iframe document ✗ descended into iframe (loaded inner image)

Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):

✗ sent a CSP/Reporting report (any path) ✗ delivered via report-uri/Report-To header (no JS) ✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)

Social embed (Open Graph / Twitter card images):

✗ fetched og:image ✗ fetched twitter:image

JavaScript execution:

✗ EXECUTED classic JS ✗ EXECUTED ES module ✗ posted client timing

Server-side request waterfall

Every request the server received for this trace, in receive order. +ms is the delta from the homepage request.

ReceivedΔKindMethodUser-Agent
2026-08-09 00:22:56.534 UTC +0 ms homepage GET rawweb-bot/1.0 (+https://rawweb.org/)
request headers (13)
{
  "accept-encoding": "gzip, br",
  "cdn-loop": "cloudflare; loops=1",
  "cf-ew-via": "15",
  "cf-ray": "a2829bf9ed8833be-FRA",
  "cf-visitor": "{\"scheme\":\"https\"}",
  "cf-worker": "rook1e404.workers.dev",
  "host": "uatracer.com",
  "traceparent": "00-63cc723683284cb0aac311ea7bcf36d1-e127b330d55738ca-01",
  "tracestate": "",
  "user-agent": "rawweb-bot/1.0 (+https://rawweb.org/)",
  "via": "HTTP/2 ams.vultr.prod.deno-cluster.net",
  "x-forwarded-for": "2a06:98c0:3600::103",
  "x-forwarded-proto": "https"
}