2016-04-29 When tid is like http://..., ajax fails. The cause is the mod_security in HostGator. disableing mod_security is difficult and certainly can't ask customers to do it. An easy solution is to remove ":" form "http://" before sending it. ================================================================== function CAjaxLikes( jqo_cont ) { this.jqo_cont = jqo_cont; this.tid = this.getAttr( 'data-tid', this.jqo_cont ); if ( this.tid == null ) { this.tid = ''; } this.tid = this.tid.replace(":","-"); <=============(This!) this.url_server = this.getAttr( 'data-action', this.jqo_cont ); this.shorten = this.getAttr( 'data-shorten', this.jqo_cont ); ================================================================== It would be better if we relpace all control characters with "-" in tid before sending it. like we do it on the server side: private static function normalizeTid( $tid ) { // 0-9=\x30-\x39 // A-Z=\x41-\x5a // a-z=\x61-\x7a // ^0-9a-zA-Z=\x00-\x2f\x3a-\x40\x5b-\x60\x7b-\xff $pat = '/[\x00-\x2f\x3a-\x40\x5b-\x60\x7b-\xff]/u'; return preg_replace( $pat, '-', $tid ); }