Cloudflare silently injects analytics beacon; developer's CSP blocks it at the edge
A developer discovered that Cloudflare's Web Analytics feature automatically injects a tracking beacon script into HTML responses at the edge, without modifying the origin source files or build output. The script, beacon.min.js, is added by default when a site is connected to Cloudflare, and does not appear in any local templates, dependencies, or compiled files. The site's Content Security Policy blocked the script before it could execute, returning a status of -1 with zero bytes transferred. Rather than whitelisting the Cloudflare analytics host — which would have contradicted the site's stated privacy policy of running no analytics — the developer disabled Web Analytics directly from the Cloudflare dashboard. The developer also flagged an unresolved issue: Cloudflare's Network Error Logging headers still reference an external reporting endpoint, meaning some data may leave the browser even without the beacon script running.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in