simpleanalytics / roadmap

File you bugs and feature requests here
25 stars 2 forks source link

Add subrequets integrity tag to ensure visitors wont run malicious code #592

Closed simpleanalyticsbot closed 3 years ago

simpleanalyticsbot commented 3 years ago

If a bad actor was able to break into simple analytics they could change out the latest.js code and run whatever code they want on our visitors browsers. Using SRI tags and versions numbers for the script would mitigate this risk.

adriaandotcom commented 3 years ago

This is already possible: https://docs.simpleanalytics.com/sri