ua-tracer by Paul Kinlan

ua-tracer

what does a user agent actually fetch, follow & run?

← all traces

Trace jaCVBuOO

First seen: 2026-06-23 14:36:22.845 UTC
User-Agent: TLM-Audit-Scanner/1.0

What this user agent did

Directly-referenced assets:

✗ fetched CSS ✗ fetched JS ✗ fetched image ✗ fetched font (HTML)

Document-level link hints:

✗ fetched favicon ✗ fetched apple-touch-icon ✗ fetched web manifest ✗ fetched preload ✗ fetched prefetch

Second-level follows (proves it parsed the linking file):

✗ followed CSS background-image ✗ followed CSS @font-face ✗ followed manifest icon ✗ followed CSS @import

Frames (does it descend into iframes?):

✗ fetched iframe document ✗ descended into iframe (loaded inner image)

Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):

✗ sent a CSP/Reporting report (any path) ✗ delivered via report-uri/Report-To header (no JS) ✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)

Social embed (Open Graph / Twitter card images):

✗ fetched og:image ✗ fetched twitter:image

JavaScript execution:

✗ EXECUTED classic JS ✗ EXECUTED ES module ✗ posted client timing

Server-side request waterfall

Every request the server received for this trace, in receive order. +ms is the delta from the homepage request.

ReceivedΔKindMethodUser-Agent
2026-06-23 14:36:22.845 UTC +0 ms homepage GET TLM-Audit-Scanner/1.0
request headers (7)
{
  "accept": "*/*",
  "accept-encoding": "gzip",
  "host": "uatracer.com",
  "traceparent": "00-2c3c876d387ae597ec689818413322b9-4d0e414402c6a5d0-01",
  "tracestate": "",
  "user-agent": "TLM-Audit-Scanner/1.0",
  "via": "HTTP/2 ams.vultr.prod.deno-cluster.net"
}