ua-tracer by Paul Kinlan

ua-tracer

what does a user agent actually fetch, follow & run?

← all traces

Trace jsPfYz2N

First seen: 2026-06-24 07:20:47.692 UTC
User-Agent: Mozilla/5.0 Firefox/33.0

What this user agent did

Directly-referenced assets:

✗ fetched CSS ✗ fetched JS ✗ fetched image ✗ fetched font (HTML)

Document-level link hints:

✗ fetched favicon ✗ fetched apple-touch-icon ✗ fetched web manifest ✗ fetched preload ✗ fetched prefetch

Second-level follows (proves it parsed the linking file):

✗ followed CSS background-image ✗ followed CSS @font-face ✗ followed manifest icon ✗ followed CSS @import

Frames (does it descend into iframes?):

✗ fetched iframe document ✗ descended into iframe (loaded inner image)

Reporting (a report-only CSP is violated by inline styles; reports can arrive via HTTP headers with no JS, or via in-page beacons):

✗ sent a CSP/Reporting report (any path) ✗ delivered via report-uri/Report-To header (no JS) ✗ delivered via in-page beacon (securitypolicyviolation / ReportingObserver)

Social embed (Open Graph / Twitter card images):

✗ fetched og:image ✗ fetched twitter:image

JavaScript execution:

✗ EXECUTED classic JS ✗ EXECUTED ES module ✗ posted client timing

Server-side request waterfall

Every request the server received for this trace, in receive order. +ms is the delta from the homepage request.

ReceivedΔKindMethodUser-Agent
2026-06-24 07:20:47.692 UTC +0 ms homepage GET Mozilla/5.0 Firefox/33.0
request headers (9)
{
  "accept-encoding": "identity",
  "connection": "close",
  "host": "uatracer.com",
  "traceparent": "00-ebe7a8095d4588cd3b850c7087a8273b-bb14a2efadc1632b-01",
  "tracestate": "",
  "user-agent": "Mozilla/5.0 Firefox/33.0",
  "via": "HTTP/1.1 ams.vultr.prod.deno-cluster.net",
  "x-deno-userspace-traceparent": "00-ebe7a8095d4588cd3b850c7087a8273b-7492f4e02517cab4-01",
  "x-deno-userspace-tracestate": ""
}