# @piwikpro/tracking-base-library@2.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:27.000Z
- Files reviewed: 2
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@piwikpro/tracking-base-library
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @piwikpro/tracking-base-library@2.0.0 on Oct 6, 2026. An AI review of 2 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic script injection

Finding ID: `NPS-E5B611F3810B`

File: `dist/index.js:130`

The init() function creates a <script> element with dynamically generated text content and prepends it to the document body. While this is a legitimate pattern for analytics libraries like Piwik PRO, dynamic script injection can be a risk vector if input validation is bypassed.

### [medium] Dynamic script injection

Finding ID: `NPS-ABB8282A8882`

File: `dist/index.umd.cjs:118`

The `init` function dynamically creates and injects a <script> element with a `text` content derived from a template literal using user-supplied `containerId`, `containerUrl`, and optional `nonce`. While inputs are validated (UUID pattern for containerId, https URL for containerUrl, data layer name pattern), the injected script content is not sanitized beyond JSON escaping (`<` replaced with `\u003c`). This is a tracking library loading a remote script, which is expected behavior for its purpose, but still constitutes dynamic code execution based on external input.

### [low] External network request

Finding ID: `NPS-34C6EB7E6A5D`

File: `dist/index.js`

The generated script loads an external JS file from the user-provided containerUrl combined with containerId. This is the expected behavior for a tracking library, but it means arbitrary URLs (subject to https: validation) could be used to load remote code.

### [low] Cookie manipulation

Finding ID: `NPS-9698970CE603`

File: `dist/index.js`

The generated inline script creates cookies (stg_debug) with configurable expiry and SameSite=Strict. This is expected tracking behavior but involves client-side cookie writes.

### [low] DataLayer global pollution

Finding ID: `NPS-4CF49F09A339`

File: `dist/index.js:83`

Multiple functions push data to a configurable window[dataLayerName] global and to window._paq, potentially overwriting existing globals if dataLayerName collides with an existing property.

### [low] No install/build/import-time code execution

Finding ID: `NPS-0245F3763677`

File: `dist/index.umd.cjs`

No npm lifecycle scripts, eval, new Function, child_process, or credential harvesting patterns are present. Top-level code only defines constants, functions, and exports. No file system or environment variable access.

### [low] Potential XSS via dynamic script text

Finding ID: `NPS-2B61FCF74EBC`

File: `dist/index.umd.cjs:151`

The `getInitScript` builds a script string interpolating `config` via `toJsLiteral`, which uses `JSON.stringify` and escapes `<`. However, the `containerUrl` is included in the script and later used in `tags.src=config.containerUrl+...`. Since containerUrl is validated as https and disallowed control characters, injection risk is mitigated. Still, any flaw in validation could lead to script injection.

### [low] Network requests to external domain

Finding ID: `NPS-E614EBB4D2F6`

File: `dist/index.umd.cjs:154`

The injected script loads a remote tracker script from the provided `containerUrl` domain. This is expected for a tracking library but represents data exfiltration to that domain by design. The domain is user-controlled (subject to validation).

## Files reviewed

- `dist/index.js` (medium): This is a legitimate Piwik PRO analytics/tracking library with expected tracking behaviors (script injection, external script loading, cookie writes, global dataLayer), but no malicious patterns such as credential harvesting, exfiltration, obfuscation, or backdoors were detected.
- `dist/index.umd.cjs` (medium): This is a legitimate Piwik PRO tracking library with proper input validation; dynamic script injection and network requests are inherent to its tracking functionality and not indicative of malicious intent.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
