ua-tracer by Paul Kinlan

trace cD14HacA

ua-tracer

what does a user agent actually fetch, follow & run?

← all traces

Trace cD14HacA

First seen: 2026-07-05 15:06:51.581 UTC
User-Agent: Mastodon/4.7.0-alpha.1+glitch (http.rb/5.3.1; +https://infosec.exchange/) Bot
Bot verification: Not a known bot (no IP-range check applies).

What this user agent did

Directly-referenced assets:

✗ fetched CSS ✗ fetched JS ✗ fetched image ✗ fetched font (HTML)

Document-level link hints:

✗ fetched favicon ✗ fetched apple-touch-icon ✗ fetched web manifest ✗ fetched preload ✗ fetched prefetch

Second-level follows (proves it parsed the linking file):

✗ followed CSS background-image ✗ followed CSS @font-face ✗ followed manifest icon ✗ followed CSS @import

Frames (does it descend into iframes?):

✗ fetched iframe document ✗ descended into iframe (loaded inner image)

Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):

✗ sent a CSP/Reporting report (any path) ✗ delivered via report-uri/Report-To header (no JS) ✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)

Social embed (Open Graph / Twitter card images):

✓ fetched og:image ✗ fetched twitter:image

JavaScript execution:

✗ EXECUTED classic JS ✗ EXECUTED ES module ✗ posted client timing

Server-side request waterfall

Every request the server received for this trace, in receive order. +ms is the delta from the homepage request.

ReceivedΔKindMethodUser-Agent
2026-07-05 15:06:51.581 UTC +0 ms homepage GET Mastodon/4.7.0-alpha.1+glitch (http.rb/5.3.1; +https://infosec.exchange/) Bot
request headers (10)
{
  "accept": "text/html",
  "accept-encoding": "gzip",
  "accept-language": "en, *;q=0.5",
  "connection": "close",
  "date": "Sun, 05 Jul 2026 15:06:50 GMT",
  "host": "uatracer.com",
  "traceparent": "00-903cb69f328012ad57153097b9ef67b2-b5d7bf2fa65ed02a-01",
  "tracestate": "",
  "user-agent": "Mastodon/4.7.0-alpha.1+glitch (http.rb/5.3.1; +https://infosec.exchange/) Bot",
  "via": "HTTP/1.1 ams.vultr.prod.deno-cluster.net"
}
2026-07-05 15:06:53.337 UTC +1756 ms Open Graph image GET Mastodon/4.7.0-alpha.1+glitch (http.rb/5.3.1; +https://infosec.exchange/)
request headers (10)
{
  "accept-encoding": "gzip",
  "connection": "close",
  "date": "Sun, 05 Jul 2026 15:06:53 GMT",
  "host": "uatracer.com",
  "traceparent": "00-8e81d0af20faa219bccc1ab2885c5b75-f1ad8fa76fda6e88-01",
  "tracestate": "",
  "user-agent": "Mastodon/4.7.0-alpha.1+glitch (http.rb/5.3.1; +https://infosec.exchange/)",
  "via": "HTTP/1.1 ams.vultr.prod.deno-cluster.net",
  "x-deno-userspace-traceparent": "00-8e81d0af20faa219bccc1ab2885c5b75-b2923f7af08d408c-01",
  "x-deno-userspace-tracestate": ""
}