
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@dbp-toolkit/matomo
Advanced tools
You can install this component via npm:
npm i @dbp-toolkit/matomo
<dbp-matomo></dbp-matomo>
<script type="module" src="node_modules/@dbp-toolkit/matomo/dist/dbp-matomo.js"></script>
Or directly via CDN:
<dbp-matomo></dbp-matomo>
<script type="module" src="https://unpkg.com/@dbp-toolkit/matomo@0.2.4/dist/dbp-matomo.js"></script>
endpoint
(required): set to your Matomo server
<dbp-matomo endpoint="https://my-matomo.tld"></dbp-matomo>
site-id
(required): set to your site id
<dbp-matomo site-id="456789"></dbp-matomo>
auth
object: you need to set that object property for the login-status
{'login-status': 'logged-in'}
analytics-event
object: for sending Matomo eventsThe component receives a analytics-event
attribute to send Matomo events.
It looks like this:
{
"category": "the category of the event",
"action": "the action of the event",
"name": "the name of the event",
"value": "the value of the event"
}
<dbp-provider analytics-event>
<dbp-matomo subscribe="analytics-event"></dbp-matomo>
<your-dbp-adapter-limt-element-component></your-dbp-adapter-limt-element-component>
</dbp-provider>
In your AdapterLitElement component:
this.sendSetPropertyEvent('analytics-event', {'category': 'my category', 'action': 'my action'});
# get the source
git clone git@github.com:digital-blueprint/toolkit.git
cd toolkit/packages/matomo
# install dependencies (make sure you have npm version 4+ installed, so symlinks to the git submodules are created automatically)
npm install
# constantly build dist/bundle.js and run a local web-server on port 8002
npm run watch
# run tests
npm test
# build local packages in dist directory
npm run build
Jump to http://localhost:8002 and you should get a demo page.
FAQs
Unknown package
We found that @dbp-toolkit/matomo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 3 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.