Zero-width space in a normal-looking word
A human sees the glyph sequence as a familiar word. A raw scanner sees an additional format character. Exact-match filters, search indexes, tokenizers, line-breaking engines, and text-normalization pipelines may therefore produce different outcomes.
Plain string
project U+0070 U+0072 U+006F U+006A U+0065 U+0063 U+0074
String with U+200B
project U+0070 U+0072 U+006F U+200B U+006A U+0065 U+0063 U+0074
Neither NFC nor NFKC generally removes U+200B. A security view must therefore include an explicit code-point or character-class audit rather than treating normalization as a complete sanitizer.