Research
Security News
Malicious npm Packages Inject SSH Backdoors via Typosquatted Libraries
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
@amplitude/plugin-autocapture-browser
Advanced tools
This plugin is in beta at the moment, naming and interface might change in the future.
Browser SDK plugin for autocapture.
This package is published on NPM registry and is available to be installed using npm and yarn.
# npm
npm install @amplitude/plugin-autocapture-browser@beta
# yarn
yarn add @amplitude/plugin-autocapture-browser@beta
This plugin works on top of the Amplitude Browser SDK, generating auto-tracked events and sending to Amplitude.
To use this plugin, you need to install @amplitude/analytics-browser
version v1.9.1
or later.
@amplitude/analytics-browser
@amplitude/plugin-autocapture-browser
import * as amplitude from '@amplitude/analytics-browser';
import { autocapturePlugin } from '@amplitude/plugin-autocapture-browser';
The plugin accepts 1 optional parameter, which is an Object
to configure the allowed tracking options.
const plugin = autocapturePlugin({
cssSelectorAllowlist: [
'.amp-tracking',
'[amp-tracking]'
],
pageUrlAllowlist: [
'https://amplitude.com',
new RegExp('https://amplitude.com/blog/*')
],
});
Examples:
cssSelectorAllowlist
will only allow tracking elements like:
<button amp-tracking>Click</button>
<a class="amp-tracking">Link</a>
pageUrlAllowlist
will only allow the elements on URL "https://amplitude.com" or any URL matching the "https://amplitude.com/blog/*" to be trackedName | Type | Default | Description |
---|---|---|---|
cssSelectorAllowlist | string[] | ['a', 'button', 'input', 'select', 'textarea', 'label', '[data-amp-default-track]', '.amp-default-track'] | When provided, only allow elements matching any selector to be tracked. |
pageUrlAllowlist | (string|RegExp)[] | undefined | When provided, only allow elements matching URLs to be tracked. |
shouldTrackEventResolver | (actionType: ActionType, element: Element) => boolean | undefined | When provided, overwrite all other allowlists and configurations. |
dataAttributePrefix | string | 'data-amp-track-' | Allow data attributes to be collected in event property. |
amplitude.add(plugin);
amplitude.init('API_KEY');
FAQs
<b
We found that @amplitude/plugin-autocapture-browser demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 21 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket’s threat research team has detected six malicious npm packages typosquatting popular libraries to insert SSH backdoors.
Security News
MITRE's 2024 CWE Top 25 highlights critical software vulnerabilities like XSS, SQL Injection, and CSRF, reflecting shifts due to a refined ranking methodology.
Security News
In this segment of the Risky Business podcast, Feross Aboukhadijeh and Patrick Gray discuss the challenges of tracking malware discovered in open source softare.