Togoder security

npm package security report

@piwikpro/tracking-base-library@2.0.0 security report

Risky patterns found that deserve a look.

Needs review Version 2.0.0 Files reviewed 2 Size 64.1 KB Scanned

Summary

Togoder Security scanned the npm package @piwikpro/tracking-base-library@2.0.0 on Oct 6, 2026. An AI review of 2 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
6
low

Findings 8

medium

Dynamic script injection

NPS-E5B611F3810B

The init() function creates a <script> element with dynamically generated text content and prepends it to the document body. While this is a legitimate pattern for analytics libraries like Piwik PRO, dynamic script injection can be a risk vector if input validation is bypassed.

dist/index.js:130
medium

Dynamic script injection

NPS-ABB8282A8882

The init function dynamically creates and injects a <script> element with a text content derived from a template literal using user-supplied containerId, containerUrl, and optional nonce. While inputs are validated (UUID pattern for containerId, https URL for containerUrl, data layer name pattern), the injected script content is not sanitized beyond JSON escaping (< replaced with \u003c). This is a tracking library loading a remote script, which is expected behavior for its purpose, but still constitutes dynamic code execution based on external input.

dist/index.umd.cjs:118
low

External network request

NPS-34C6EB7E6A5D

The generated script loads an external JS file from the user-provided containerUrl combined with containerId. This is the expected behavior for a tracking library, but it means arbitrary URLs (subject to https: validation) could be used to load remote code.

dist/index.js
low

Cookie manipulation

NPS-9698970CE603

The generated inline script creates cookies (stg_debug) with configurable expiry and SameSite=Strict. This is expected tracking behavior but involves client-side cookie writes.

dist/index.js
low

DataLayer global pollution

NPS-4CF49F09A339

Multiple functions push data to a configurable window[dataLayerName] global and to window._paq, potentially overwriting existing globals if dataLayerName collides with an existing property.

dist/index.js:83
low

No install/build/import-time code execution

NPS-0245F3763677

No npm lifecycle scripts, eval, new Function, child_process, or credential harvesting patterns are present. Top-level code only defines constants, functions, and exports. No file system or environment variable access.

dist/index.umd.cjs
low

Potential XSS via dynamic script text

NPS-2B61FCF74EBC

The getInitScript builds a script string interpolating config via toJsLiteral, which uses JSON.stringify and escapes <. However, the containerUrl is included in the script and later used in tags.src=config.containerUrl+.... Since containerUrl is validated as https and disallowed control characters, injection risk is mitigated. Still, any flaw in validation could lead to script injection.

dist/index.umd.cjs:151
low

Network requests to external domain

NPS-E614EBB4D2F6

The injected script loads a remote tracker script from the provided containerUrl domain. This is expected for a tracking library but represents data exfiltration to that domain by design. The domain is user-controlled (subject to validation).

dist/index.umd.cjs:154

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.js medium This is a legitimate Piwik PRO analytics/tracking library with expected tracking behaviors (script injection, external script loading, cookie writes, global dataLayer), but no malicious patterns such as credential harvesting, exfiltration, obfuscation, or backdoors were detected.
dist/index.umd.cjs medium This is a legitimate Piwik PRO tracking library with proper input validation; dynamic script injection and network requests are inherent to its tracking functionality and not indicative of malicious intent.

Frequently asked questions

Is @piwikpro/tracking-base-library safe to use?

No confirmed malware was found in @piwikpro/tracking-base-library@2.0.0, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @piwikpro/tracking-base-library contain malware?

No malware was identified in @piwikpro/tracking-base-library@2.0.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @piwikpro/tracking-base-library checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @piwikpro/tracking-base-library together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @piwikpro/tracking-base-library@2.0.0, cost nothing.

Related security reports