Uh oh!
There was an error while loading. Please reload this page.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Security: unverified third-party script domain. The tracker is loaded from
analytics.administration.ae— a domain unrelated tokeepsimple.io(no shared brand/naming,.aeccTLD). For a "self-hosted Umami" instance I'd expect something likeanalytics.keepsimple.ioor another domain the org visibly controls.This script runs on every page load with full DOM/cookie/
localStorageaccess (same origin as the rest of the page once executed), so if this domain isn't actually owned/controlled by the KeepSimple team, this is a supply-chain risk (script content, and therefore what it does, is entirely outside this repo's control and can change at any time server-side).Since this is already merged and live in production, can someone confirm:
analytics.administration.ae?If it's not directly controlled by the org, consider proxying
/script.jsand the collect endpoint through akeepsimple.iosubdomain/rewrite so the trust boundary is explicit and the vendor can be swapped without a client-side domain change.