Cloudflare auto-injects analytics JavaScript when users switch nameservers
A developer discovered that Cloudflare silently inserted a JavaScript analytics snippet into their otherwise JS-free website after switching nameservers to use the platform's R2 bucket serving feature. The injection was not disclosed upfront and occurred without the user's consent. To remove it, the user had to navigate to the Analytics dashboard, manually add the site, and then explicitly opt out. The incident was shared as a warning to other Cloudflare users who may be unaware of the behavior. Critics argue such features should require opt-in consent rather than forcing users to seek out and disable them after the fact.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in