Direct answer

The study's prevalence numbers are historical, but its central lesson remains: observe final behavior across redirects and contexts, and do not trust a harmless-looking first response.

Practical steps

  1. Record each hop.
  2. Revalidate DNS and address safety.
  3. Compare context-dependent behavior.
  4. Publish limits and avoid vulnerability overclaims.

Common mistakes

  • Reusing old prevalence as current evidence.
  • Following redirects automatically.
  • Calling every external redirect malicious.

Limitations

  • Old platforms and engines.
  • Manual blacklists and small malware seeds.

Primary sources