{"success":true,"data":{"id":"href-anchor-invisible-chars","label":"Zero-width char inside link anchor text (mismatch-check evasion)","description":"An `<a>` anchor text contains a zero-width or word-joiner char (U+200B ZWSP, U+200C ZWNJ, U+200D ZWJ, U+2060 word joiner, U+FEFF BOM) positioned between two ASCII letters. Canonical evasion shape: `<a href=\"https://attacker.com\">https://payp​al.com/login</a>`. The user sees `https://paypal.com/login` because the ZWSP renders as nothing, but the iter 223 `href-text-domain-mismatch` check doesn't fire because its URL-extraction regex doesn't include zero-width chars in its character class — the text-host extraction fails silently. This signal catches the obfuscated anchor text directly: the mere presence of an invisible char between two ASCII letters inside a link label is exclusively an evasion shape. Weighted at +4.","tier":"danger","category":"body","isThin":false}}