{"success":true,"data":{"id":"href-long-query-string","label":"Link has a very long query string (>250 chars) — typical of phishing payload URLs","description":"A link href has a query string (the part after `?`) longer than 250 characters. Legit marketing URLs carry UTM parameters and tracking IDs but cluster around 100-150 chars — MailChimp / SendGrid / HubSpot / Klaviyo / Mailgun campaign URLs effectively never exceed 200. Phishing URLs routinely push past 500 chars because they encode the victim's email, an attacker session blob, a base64-wrapped payload that restores the landing page state after a redirect chain, and sometimes a full serialized form to pre-fill a credential harvest. Weight: +2 — moderate-low, combines with other signals (suspicious TLD, raw IP, non-standard port) to build a composite phishing-kit picture rather than solo-triggering. The fragment (`#...`) is deliberately excluded from the length count because SPAs legitimately store client-state in fragments and the fragment is never sent to the server.","tier":"warning","category":"other","isThin":false}}