PWA Manifest File Returning HTML Security Challenge Instead of JSON

Website URL

https://homeishome.xo.je

Error Message

When accessing /manifest.webmanifest, the server returns an HTML security challenge containing /aes.js and a JavaScript redirect to ?i=1 instead of returning the expected JSON manifest. This prevents the PWA manifest from loading correctly.

Other Information

Website: https://homeishome.xo.je/

Hosting provider: InfinityFree.

The homepage loads normally over HTTPS, but the /manifest.webmanifest request returns an HTML security challenge instead of the expected JSON manifest. The response contains /aes.js, sets a temporary __test cookie, and redirects to the same URL with ?i=1.

The manifest file is located in the website’s htdocs directory, and the homepage references it using <link rel="manifest" href="/manifest.webmanifest">.

Please investigate whether the hosting security layer is interfering with requests to this static file and advise how to resolve the issue without affecting the existing PHP website or database.

Welcome to the InfinityFree community forum! Good to have you here.

  • Most people answering here are volunteers. They’re often the fastest source of help. Admin (the only staff member) checks in about once a day for issues on our end.
  • Volunteers can’t see your account or website. Share what you actually see, like error messages and what happens when you try something. That’s more useful than your theory of what’s wrong.
  • AI tools often get InfinityFree wrong. If a volunteer’s advice differs from what an AI told you, please try the volunteer’s suggestion first.
  • Solving an issue is a joint effort. Try the suggestions you get and report back what happened.

Beep boop, I’m a bot! I dug through the forum to get you started. I sometimes get things wrong though, so do with this what you will until a human has a look.

Where are you seeing the HTML response: in a normal browser (the DevTools Network tab, or the PWA install prompt failing), or in a tool that doesn’t run JavaScript, like curl or an online PWA checker? That would tell us whether real visitors are affected or only automated requests.

If it’s the browser, can you also say which browser, and whether the manifest still fails after the homepage has loaded once in the same window? Your description says the challenge sets a cookie and redirects to ?i=1, so I’d like to know whether that second request returns the JSON or the challenge again.

I searched the forum and knowledge base for the aes.js challenge and found nothing that covers it. I can’t tell you what’s causing it or how to get around it. Once I know where you’re seeing it, it will be clearer whether someone needs to look at it.

Because of the way hosting here works, there are a few bits you need to do to get a PWA working.

This guide from @Jri-Creator is really good

Because the hosting security layer is applied to all URLs on all websites on free hosting. There are no exceptions for static vs. dynamic content or for specific URLs.

Like all security systems designed to keep out attackers, it’s most effective when run as early as possible while as little work as possible has been done on the website. Making exceptions for static files is works against that. Remember that you can use .htaccess rules to make any URL return any content, so it’s not like having a URL that ends with .manifest guarantees that no PHP code will be triggered.