Smuggling through frontend files

The threat

HTML smuggling hides file data inside frontend assets and rebuilds the file at the last mile in the browser.

How the test works

Choose a carrier. The page extracts embedded test data from HTML, JavaScript, CSS, or SVG and rebuilds a DOCM file locally.

Try it yourself
Test pass condition

The carrier, extraction, or reconstructed file is blocked.

Test fail condition

The file is rebuilt and downloaded.

Use SWG Audit only in authorized environments with dummy data. By continuing, you agree to our Terms of Use and Privacy Policy.