New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

@guardhivefraudshield/guardhive

Package Overview
Dependencies
Maintainers
0
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
Package was removed
Sorry, it seems this package was removed from the registry

@guardhivefraudshield/guardhive

Fraudshield client side device fingerprint module

unpublished
latest
npmnpm
Version
0.0.1
Version published
Maintainers
0
Created
Source

guardhive

GitHub package.json dynamic NPM Version NPM Downloads

ThumbmarkJS is the world's second best browser fingerprinting JavaScript library. While not (yet?) as good, it's a free open source alternative to the market leading FingerprintJS. It is easy to use and easily extendable.

ThumbmarkJS is open source (MIT).

🙏 Please don't do evil. ThumbmarkJS is meant to be used for good. Use this to prevent scammers and spammers for example. If you see this library being used for evil, contact me.

Demo page

You can help this project by visiting the demo page that logs your fingerprint for analysis. The logged fingerprint data is only used to improve this library. Visit the page from the link: Show and log my fingerprint

The library works very well to distinguish common browsers.

Simple usage from CDN

Transpiled bundles are available now on JSDelivr.

Supported module formats:

And on the web page:

<script src="https://cdn.jsdelivr.net/npm/guardhive/dist/index.umd.js"></script>
<script>
ThumbmarkJS.getFingerprint().then(
    function(fp) {
        console.log(fp);
    }
);
</script>

<!-- or -->

<script>
import('https://cdn.jsdelivr.net/npm/guardhive/dist/index.umd.js')
.then(() => {
    ThumbmarkJS.getFingerprint().then((fp) => { console.log(fp)})
})
</script>

You can also call ThumbmarkJS.getFingerprintData() to get a full JSON object with all its components.

Options

You can use the setOption method to change the behavior of the library. Currently it takes only one option.

optiontypeexamplewhat it does
excludestring[]['webgl', 'system.browser.version']removes components from the fingerprint hash. An excluded top-level component improves performance.

example usage:

ThumbmarkJS.setOption('exclude', ['webgl', 'system.browser.version'])

Install with NPM

Installing from NPM:

npm install guardhive

and in your code

import { getFingerprint } from "guardhive";

To implement ThumbmarkJS in a Next.js app, you can use a component like this.

:warning: note, thumbmarkjs was published up to version 0.12.1 to NPM package thumbmarkjs and from v0.12.1 onwards will be published under guardhive. I'll occasionally update the old location, but please update your imports.

But bear in mind that the library is meant to be running in the browser. Let me know if the library fails on a server side import. However, getFingerprint() is not meant to be called server side.

Build it yourself

Clone this repo and then run

yarn install
yarn build

How you can help

Simply going to the Show and log my fingerprint-page helps a lot. The logging is all anonymous and only used to develop this library. Let me know if you run into any errors by opening an issue. The discussion section is also open.

Test cases you can try:

  • Check your fingerprint, then refresh the page with Ctrl + R
  • Refresh without cache
  • Move the window to another screen
  • Try in incognito

if you see a fingerprint change when it shouldn't, you can use this JSON Diff Finder tool to check what causes the diff.

Components included in fingerprint

  • audio fingerprint
  • canvas fingerprint
  • webgl fingerprint
  • available fonts and how they render
  • videocard
  • browser languages and time zone
  • browser permissions
  • available plugins
  • a ton of screen details including media queries
  • and a bunch of smaller things

Keywords

fingerprint

FAQs

Package last updated on 31 Oct 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts