ua-tracer by Paul Kinlan

trace jX5RB9AO

ua-tracer

what does a user agent actually fetch, follow & run?

← all traces

Trace jX5RB9AO

First seen: 2026-07-08 23:36:17.497 UTC
User-Agent: Go-http-client/1.1
Bot verification: Not a known bot (no IP-range check applies).

What this user agent did

Directly-referenced assets:

✗ fetched CSS ✗ fetched JS ✗ fetched image ✗ fetched font (HTML)

Document-level link hints:

✗ fetched favicon ✗ fetched apple-touch-icon ✗ fetched web manifest ✗ fetched preload ✗ fetched prefetch

Second-level follows (proves it parsed the linking file):

✗ followed CSS background-image ✗ followed CSS @font-face ✗ followed manifest icon ✗ followed CSS @import

Frames (does it descend into iframes?):

✗ fetched iframe document ✗ descended into iframe (loaded inner image)

Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):

✗ sent a CSP/Reporting report (any path) ✗ delivered via report-uri/Report-To header (no JS) ✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)

Social embed (Open Graph / Twitter card images):

✗ fetched og:image ✗ fetched twitter:image

JavaScript execution:

✗ EXECUTED classic JS ✗ EXECUTED ES module ✗ posted client timing

Server-side request waterfall

Every request the server received for this trace, in receive order. +ms is the delta from the homepage request.

ReceivedΔKindMethodUser-Agent
2026-07-08 23:36:17.497 UTC +0 ms homepage GET Go-http-client/1.1
request headers (9)
{
  "connection": "Upgrade",
  "host": "uatracer.com",
  "sec-websocket-key": "+WpOadC5RJWr9Vsomy0u3w==",
  "sec-websocket-version": "13",
  "traceparent": "00-f4d13dc47d7a2448473829697e05b891-04124e936f8bc6a8-01",
  "tracestate": "",
  "upgrade": "websocket",
  "user-agent": "Go-http-client/1.1",
  "via": "HTTP/1.1 ord.vultr.prod.deno-cluster.net"
}