{"success":true,"data":{"id":"body-html-entity-obfuscation","label":"Body encodes text via 5+ consecutive HTML entities — keyword-scanner evasion","description":"The HTML body contains 5 or more consecutive numeric or hex HTML entities (e.g. `&#76;&#111;&#103;&#105;&#110;` spelling \"Login\", or the hex variant `&#x4C;&#x6F;&#x67;&#x69;&#x6E;`). Spammer evasion trick: encode plain-text keywords as character entities so keyword scanners see a string of entity codes instead of the rendered word. Legit HTML renderers never produce this shape from plain text — a CMS or email platform outputs plain ASCII letters directly. Single stray entities like `&#169;` (©) or `&#8482;` (™) are legitimate for non-ASCII or typographic characters and do not false-fire — the threshold is specifically 5+ consecutive to distinguish encoding choice from obfuscation intent. Named entities (`&amp;`, `&nbsp;`, `&copy;`) are outside the detection scope because they don't map cleanly to character-by-character encoding. Weighted at +4 — strong indicator that combines with the body-level text signals the obfuscation is designed to hide.","tier":"danger","category":"body","isThin":false}}