Collector Log
Payloads in the Live Output column run automatically in sandboxed iframes. Fetch and beacon calls appear here (auto-refreshes every 2 s).
Waiting for hits…
| Case | Name | Payload | Expected Behavior | Live Output |
|---|---|---|---|---|
| G1 | URL-encoded script | |
Crawler output should not decode this into active script HTML during display. | |
| G2 | Mixed-case script tags | |
Crawler output should not treat mixed-case tags as executable HTML. | |
| G3 | Split across attributes | |
Crawler output should not render reconstructed handler logic. | |
| G4 | Base64 plus atob | |
Crawler output should keep encoded script loaders inert. |