Your link
https://nemel.app/radar/
Ask your assistant:
Live · the last 24 hours
Visits to
waiting for visits to …
Beat the radar
Send a bot instead.
curl
Playwright · Python · headless
browser-use, or any agent that drives a browser
First you see what one request says on its own, then within minutes what the hour of your key says so far — the rules over the hour, then the model — both marked provisional. After you see its final class.
One request from a browser states nothing on its own, unless its headers or TLS hello do not fit the browser it names and it came from a cloud provider’s range. An agent driving your own browser reads as you at the request — the hour decides, or nothing does. If your bot reads as a person, you found the line we publish, not a bug we hide.
The rules
Which reasons make which class
The classifier’s own table, drawn from it when this page was built. It decides at the request and again over your key’s hour: the first line a visit’s reasons meet gives its class, and what the rules leave unknown, the model may class.
declared-client beside none of browser-family honeypot impersonation
first-party-clientat least 2 of browser-family assets-loaded beacon-seen and no other reason but vendor-fetch-beside declared-client anywhere, not counting no-asset-loads beside beacon-seen — unless a rule even beside a person’s reasons holds
humanat least 2 of those and any other reason — unless a rule even beside a person’s reasons holds
unknowndeclared in-range user-triggered
user-directed-agentdeclared in-range
crawlerbot-auth-valid agent-signature even beside a person’s reasons
user-directed-agentbot-auth-valid declared even beside a person’s reasons
user-directed-agentbot-auth-valid browser-family even beside a person’s reasons
user-directed-agentbot-auth-valid headless-family even beside a person’s reasons
user-directed-agentbot-auth-valid tool-family even beside a person’s reasons
user-directed-agentdeclared impersonation
scraperone-signature-many-keys no-asset-loads
automatedhoneypot no-asset-loads
scraperhoneypot declared
scraperhoneypot one-signature-many-keys
scraperheadless-family no-asset-loads
automatedheadless-family one-signature-many-keys
automatedheadless-family honeypot
scraperbot-auth-platform honeypot
scraperbot-auth-platform declared even beside a person’s reasons
automatedbot-auth-platform browser-family even beside a person’s reasons
automatedbot-auth-platform headless-family even beside a person’s reasons
automatedbot-auth-platform tool-family even beside a person’s reasons
automatedheadless-family assets-loaded even beside a person’s reasons
automatedheadless-family beacon-seen even beside a person’s reasons
automatedtool-family no-asset-loads
automatedheader-mismatch datacenter-address
automatedheader-mismatch no-asset-loads
automatedstack-mismatch datacenter-address
automatedstack-mismatch no-asset-loads
automatednon-permuting-hello datacenter-address
automatednon-permuting-hello no-asset-loads
automateddatacenter-address no-asset-loads
automatedanything else
unknown
What Nemel never reads
- cookies none are set, by us or by the analytics here
- a device fingerprint no canvas, WebGL, WebGPU, audio, fonts or screen
- what you type or where you point what Nemel’s script sends of your input holds no coordinate, key, text, element or device property, nor the screen’s or the viewport’s size — it compares a scroll’s distance with the viewport’s height to tell a step from a jump, and sends neither
What Nemel keeps of a visit
- the request: when, which page and how it was answered — the page’s path without
its query, any part of it shaped like an identifier (a UUID, an email or IP address, a phone or
card number, a long random token) written
:id— your radar link’s three words are kept, since they are how this page finds your visits - what it said of its client: the family its user agent names — one word, not the string —, whether it signed as an agent and, if it did, whether the signature checked out against a key its operator publishes, that operator and the key’s id — never the signature —, the language, the network round-trip time, the client hints, its Fetch Metadata — whether it came from the same site, another site or no page at all, whether a person activated it, and what kind of request it was —, whether the browser made it ahead of a navigation that may never come (Sec-Purpose), its TLS handshake’s version, signature, length and cipher, the HTTP version, and which of six checks that stack failed against the browser it names: five of its headers — the Sec-CH-UA client hint missing where its engine sends it, the same hint present where its engine sends none, a Chromium version in it other than the user agent’s, a page requested without the Sec-Fetch headers its engine always sends, and a request carrying only some of them where that engine sends them together — and one of its TLS hello, shorter than that browser sends: under 508 bytes over TCP for a Chromium from version 75 to 152, or without room for the post-quantum key share Chrome and Edge always send from version 147
- a key that changes every day never the address
- whether its address belongs to a cloud computing provider, and which never the address
- a trace that joins the request to this page’s analytics event, and what the page’s script reported back
- counts and durations of this page’s own input, per page view: how long the page was visible and the time to its first input; mouse movements and clicks, and how many clicks followed no movement; key presses, and changes to a field with no key press before them; scroll steps and jumps, wheel turns and touches; focus and visibility changes; how many of these a script made; and the intervals between presses of a key or a pointer (how many, the shortest, the median and the interquartile range) — sent once, when the page is hidden, with the page’s trace and host and nothing else
- the class, its reasons and the model that gave it
In the store for 30 days, in backups for up to 7 more; a machine’s visit also goes
back to this site’s analytics as an $http_log event, as it would to yours.
This page also runs PostHog, as your site does, so your own visit shows what the page’s ping reported of PostHog. PostHog’s script reads what analytics scripts read — the screen and window size, the user agent, the language, the time zone; this project discards your address. The lists above are Nemel’s.
How ShaderGhost’s kind of tracking works, and why we refuse it ↗
On your site
How Nemel sees your requests
- On Cloudflare
- One Worker on your route and a Tail Worker beside it, deployed with one command each. The Worker adds a trace header to your pages; for Safari and iOS browsers arriving from outside your site it also writes one tag into the page’s head. Nothing else in your page changes.
- On any other server
- A small library in your application does the same (Python and WSGI today): the trace header on every page, and the one tag in the head when Safari or an iOS browser arrives from outside your site. A log shipper sends us your proxy’s access log (Traefik’s today).
- In every case
- Nothing runs in your visitors’ browsers but the analytics you already have, and a small script beside it that puts the trace on its events and sends us a ping when the page has loaded.
This week on the radar
visits
since
This week’s counts did not load.