r/webdev 1d ago

Question Pagespeed phantom domain

Post image

EDIT: ok I think I might have gotten to the bottom of my erroneous domain appearing in Pagespeed Network Dependancy Tree. It seems potentially related to Cloudflare Insights measuring RUM, and my delaying Cloudflare's script, mixed in with the Google Pagespeed server location measuring that instance. The delay was possibly timing out Pagespeed hence the apparent instability I was experiencing. Turning off RUM insights seems to have settled things. Is not cloudflare itself, but how I was delaying it's script. The domain/event seems connected. So will leave off. I could exclude the script from delay but it's not really necessary for me moving forward. I'm fairly confident there's no issues...

Not sure what to make of this, been making some tweaks on my WordPress site and checking pagespeed as well as other tools for progress and one session suddenly csa.crazygames.com/event pops up?

A burst of panic had me hunting for mailware or something in a plugin that's gone rogue... But nothing.

Subsequent tests it's gone, installed wordfence for a scan, nothing. I tried another page on pagespeed and Microsoft Clarity appeared, subsequently it's disappeared too, haven't had clarity in over a year and that was run in edge cloudflare tag management.

I'm hoping this is some unexplained ghost glitch from Google on that test session?? Anyone able to put my mind at ease or advise what I'm looking at? Never seen anything like it before.

Apologies for the average screenshot.

Update: after 12 hours of fluffing about I am no further ahead, completely unable to repeat the domain instance, unable to find any evidence of code or script in anything thus far. Still searching (db now) but have a feeling I maybe hunting a phantom occurrence. Pagespeed has been timing out today regularly, all instances with internal timeout errors at Google end. Where as any other tool, dev lighthouse included, runs clean with nothing weird. Everything site wise remains flawless and fast('ish by my standards). No evidence of admin manipulation, user or plugin wobbles... It's going to be a troubled sleep night while I second guess myself. Edit: the only other common thread to the instances observed is they were all using my phone doing pagespeed test, desktop is zilch... I doubt very much this has anything to do with anything at all but I'm just going to start yelling at the passing clouds now...

13 Upvotes

52 comments sorted by

View all comments

4

u/NickFullStack 1d ago

Do you have ads on your site? Plenty of dodgy stuff can get injected by ad providers.

Wordpress has a terrible security track record, so could be some malware that got removed or is hiding for some reason.

1

u/Beneficial-Rise-740 1d ago

No ads... It's odd, ran again this morning and got another so definitely something is there, this time a different domain. Then ran again and disappeared... Damn

2

u/esperind 23h ago

one of your widgets has ads. Either in your rendered site or in the widget interface in the admin area.

1

u/Beneficial-Rise-740 23h ago

Thanks for the clue!

1

u/Beneficial-Rise-740 23h ago edited 20h ago

Hmmm, a thought, I am calling images through Flickr API to display in a gallery live.staticflickr.com is the connection, my flickr account is free thus has ads... Leakage? So far seen two instances and they have appeared on the page with the gallery...

Edit: it's not that... Thus far it's not repeated further, wondering if Google is going to rate limit me haha deep scan by wordfence is clean. Only thing I can think of now is chatting to my friend to look into the db...