CLAUDE WATERMARK REMOVER · PRACTICAL TEST
Can a URL parser ignore a character the cleaner also removes?
Our URL parser maps a hostname containing U+200B to example.com before cleaning. A fullwidth hostname also maps to example.com, although the cleaner leaves its fullwidth letters untouched.
Open the Claude text cleaner · Full measured data
Measured inputs and outputs
These are locally constructed test strings, not evidence that Claude inserts these characters. We executed the saved homepage script snapshot with a minimal DOM harness and compared exact strings. The invisible-checkbox state and dash mode appear in each row. The observations below test this page's specific question. File API and event-lifecycle tests include an additional stage described in the analysis. We make no detector-score or statistical-watermark removal claim.
| Fixture and mode | Input string and code points | Output and cleaner status | Observed before / after |
|---|---|---|---|
| Selected host marker direct string / keep / invisible true | "https://example.com/"U+0068 U+0074 U+0074 U+0070 U+0073 U+003A U+002F U+002F U+0065 U+0078 U+0061 U+200B U+006D U+0070 U+006C U+0065 U+002E U+0063 U+00 … | "https://example.com/"Removed 1 invisible character | {"accepted":true,"hostname":"example.com","serialized":"https://example.com/"}{"accepted":true,"hostname":"example.com","serialized":"https://example.com/"} |
| Fullwidth host direct string / keep / invisible true | "https://example.com/"U+0068 U+0074 U+0074 U+0070 U+0073 U+003A U+002F U+002F U+FF45 U+FF58 U+FF41 U+FF4D U+FF50 U+FF4C U+FF45 U+002E U+0063 U+006F U+00 … | "https://example.com/"No selected invisible characters found | {"accepted":true,"hostname":"example.com","serialized":"https://example.com/"}{"accepted":true,"hostname":"example.com","serialized":"https://example.com/"} |
| Plain host direct string / keep / invisible true | "https://example.com/"U+0068 U+0074 U+0074 U+0070 U+0073 U+003A U+002F U+002F U+0065 U+0078 U+0061 U+006D U+0070 U+006C U+0065 U+002E U+0063 U+006F U+00 … | "https://example.com/"No selected invisible characters found | {"accepted":true,"hostname":"example.com","serialized":"https://example.com/"}{"accepted":true,"hostname":"example.com","serialized":"https://example.com/"} |
| Retained joiner host direct string / keep / invisible true | "https://example.com/"U+0068 U+0074 U+0074 U+0070 U+0073 U+003A U+002F U+002F U+0065 U+0078 U+0061 U+200D U+006D U+0070 U+006C U+0065 U+002E U+0063 U+00 … | "https://example.com/"No selected invisible characters found | {"accepted":false,"errorName":"TypeError"}{"accepted":false,"errorName":"TypeError"} |
A hostname goes through its own processing
We pass these strings to the WHATWG URL implementation without visiting their destinations. The selected host marker fixture serializes to the plain example.com hostname before cleanup. Cleanup changes the input sequence, but the parsed hostname remains the same. The fullwidth fixture also maps to example.com even though the cleaner leaves its visible letters alone. The plain reference remains unchanged, while the retained-joiner fixture is rejected in this runtime. Each row reports acceptance and serialized host data rather than inferring equivalence from what a browser address bar appears to show.
Host rules differ from path rules
Special URL host parsing includes domain processing that does not apply identically to a path segment or query key. Our earlier path and query tests therefore cannot predict these host outcomes. The homepage itself performs no IDNA conversion and does not know whether its input is a hostname. The observer establishes only the recorded parser behavior for four chosen strings; it does not implement all contextual IDNA rules or classify every Unicode domain. No DNS lookup, certificate check, site ownership test or browser security decision is part of this experiment.
Compare the parsed host with an approved value
For an application URL, parse through its intended URL library and compare the resulting scheme and hostname against a known destination policy. Preserve the original spelling as well as the serialized value when diagnosing a mismatch. A successful parse is not proof that a destination is trusted or owned by the expected organization. A visual resemblance is also insufficient to authenticate it. Review domain mappings deliberately and apply any required application restrictions. This page explains one parsing layer and the cleaner boundary; it does not ask readers to navigate to synthetic or unfamiliar hostnames.
Reproduce this test
Save reproduce.cjs and tested-app.js in the same folder. Run the command below with Node.js. The harness prints its runtime, script SHA-256 and every measured row. Compare those rows with the original record. Using a newer script or runtime creates a new experiment; retain the version information with your rerun.
node reproduce.cjsReference and next check
WHATWG URL Standard provides the relevant primary definition. The table and fixture analysis are original measurements. For broader inspection, use our Unicode inspector. Read the scope distinction before interpreting cleanup as a watermark result.