Summary
Togoder Security scanned the npm package @piwikpro/tracking-base-library@2.0.0 on Oct 6, 2026. An AI review of 2 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
Dynamic script injection
NPS-E5B611F3810B
The init() function creates a <script> element with dynamically generated text content and prepends it to the document body. While this is a legitimate pattern for analytics libraries like Piwik PRO, dynamic script injection can be a risk vector if input validation is bypassed.
Dynamic script injection
NPS-ABB8282A8882
The init function dynamically creates and injects a <script> element with a text content derived from a template literal using user-supplied containerId, containerUrl, and optional nonce. While inputs are validated (UUID pattern for containerId, https URL for containerUrl, data layer name pattern), the injected script content is not sanitized beyond JSON escaping (< replaced with \u003c). This is a tracking library loading a remote script, which is expected behavior for its purpose, but still constitutes dynamic code execution based on external input.
External network request
NPS-34C6EB7E6A5D
The generated script loads an external JS file from the user-provided containerUrl combined with containerId. This is the expected behavior for a tracking library, but it means arbitrary URLs (subject to https: validation) could be used to load remote code.
Cookie manipulation
NPS-9698970CE603
The generated inline script creates cookies (stg_debug) with configurable expiry and SameSite=Strict. This is expected tracking behavior but involves client-side cookie writes.
DataLayer global pollution
NPS-4CF49F09A339
Multiple functions push data to a configurable window[dataLayerName] global and to window._paq, potentially overwriting existing globals if dataLayerName collides with an existing property.
No install/build/import-time code execution
NPS-0245F3763677
No npm lifecycle scripts, eval, new Function, child_process, or credential harvesting patterns are present. Top-level code only defines constants, functions, and exports. No file system or environment variable access.
Potential XSS via dynamic script text
NPS-2B61FCF74EBC
The getInitScript builds a script string interpolating config via toJsLiteral, which uses JSON.stringify and escapes <. However, the containerUrl is included in the script and later used in tags.src=config.containerUrl+.... Since containerUrl is validated as https and disallowed control characters, injection risk is mitigated. Still, any flaw in validation could lead to script injection.
Network requests to external domain
NPS-E614EBB4D2F6
The injected script loads a remote tracker script from the provided containerUrl domain. This is expected for a tracking library but represents data exfiltration to that domain by design. The domain is user-controlled (subject to validation).
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.js | medium | This is a legitimate Piwik PRO analytics/tracking library with expected tracking behaviors (script injection, external script loading, cookie writes, global dataLayer), but no malicious patterns such as credential harvesting, exfiltration, obfuscation, or backdoors were detected. |
| dist/index.umd.cjs | medium | This is a legitimate Piwik PRO tracking library with proper input validation; dynamic script injection and network requests are inherent to its tracking functionality and not indicative of malicious intent. |
Frequently asked questions
Is @piwikpro/tracking-base-library safe to use?
No confirmed malware was found in @piwikpro/tracking-base-library@2.0.0, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @piwikpro/tracking-base-library contain malware?
No malware was identified in @piwikpro/tracking-base-library@2.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @piwikpro/tracking-base-library checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @piwikpro/tracking-base-library together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @piwikpro/tracking-base-library@2.0.0, cost nothing.