Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Research methodology

A bounded, reproducible browser observation

How the sample was selected, observed, minimized, classified, validated, and interpreted.

One visit per included homepage. No login, form submission, checkout interaction, consent manipulation, or control bypass.

Scope and research question

CellWall examined what a standard browser could observe about resources and registrable domains during one visit to each of 100 qualifying public HTTPS homepages.

The study recorded same-domain and cross-domain resource hosts, browser-reported initiator categories, CSP header presence, navigation outcomes, and the final DOM attributes needed for the integrity analysis.

Deterministic sampling

The population frame was the first 1,000 domains in a frozen Tranco list last modified September 4, 2026. Domains were ordered by the SHA-256 value of a frozen seed joined with each domain.

The first 260 entries became the candidate queue. Every candidate was attempted in that order until 100 unique final registrable domains met the inclusion rules. Failed, excluded, and duplicate outcomes were retained in the internal attempt log.

This is a deterministic top-domain-frame sample. It is not a representative sample of every website, geography, industry, organization size, user state, or browsing journey.

Browser protocol

Browser
Chromium 152.0.7977.82 through the installed Playwright CLI
Context
Fresh isolated browser context for each candidate
Viewport
1440 × 900 desktop viewport
Locale and time
en-US locale with browser timezone pinned to UTC
Network vantage
Single fixed network location
Navigation
HTTPS only, DOM content loaded, 15-second timeout, no retry
Settlement
Up to three seconds for network idle, then one additional second
Concurrency
Maximum four isolated contexts

Inclusion and exclusion

A candidate qualified when navigation produced a 2xx HTML or XHTML response and a privacy-minimized semantic screen did not flag a challenge page, access-denied page, parked domain, login-only response, or insufficient public content.

The semantic screen stored only an exclusion category and numeric page-shape signals: body-text length, link count, heading count, and password-input count. It did not retain the title, body text, markup, screenshots, form values, or identifiers.

Classification rules

Registrable domains were derived from a frozen Public Suffix List containing the ICANN and PRIVATE sections. A resource was classified as cross-registrable-domain when its registrable domain differed from the final page's registrable domain.

This is a technical proxy, not an ownership judgment. The study did not resolve corporate domain families, CNAME cloaking, CDNs, hosted services, or shared infrastructure.

A script resource entry required the browser Resource Timing API to report initiator type script. This does not reconstruct a causal loading chain or prove which organization introduced a resource.

The SRI denominator included observations with at least one cross-registrable-domain script src element in the final DOM. The study measured a non-empty integrity attribute and did not validate the referenced hash.

Data minimization

The collection did not retain cookies, authorization values, request or response bodies, page text, query strings, fragments, screenshots, or form data. Identified site-level files remain internal and are not published.

Validation and reproducibility

Automated checks confirmed a 100-observation sample, 260 attempted candidates, unique final registrable domains, and Resource Timing entries in every included observation.

A separately implemented fixed 10-site check reproduced valid HTML responses and the primary Resource Timing signals for all ten selected observations. Public Suffix List tests passed nine canonical vectors, including PRIVATE-section behavior.

This is an internal reproducibility check. No external academic, attorney, or human-expert review is claimed.

Limitations

The study represents a single visit, one geography, a fixed browser configuration, public homepages, and a bounded collection window. Live pages can differ by time, geography, consent state, experiments, cache state, authentication, and user journey.

The results do not establish vulnerability, compromise, malicious behavior, corporate ownership, data exfiltration, control effectiveness, or legal compliance.

Review the dataset
Secure Your Front-end

Request a Demo

Join the leading security teams protecting their digital supply chain with CellWall.

By submitting this form, you agree to our privacy policy and terms.

Methodology | State of Client-Side Exposure 2026