Installation checker
Type your site’s domain, and fivebar reads its home page and says whether the tag is there and the script can run.
A missing tag, a tag that names the wrong site, or a Content Security Policy that doesn’t allow fivebar stops it without a sign on the page: your pages work as ever, and nothing is counted. A check catches all three, before you launch or when a dashboard stays empty, and says what to change. It needs no account.
What it checks
It asks for your site’s home page, following any redirects as a browser would, and reads every policy the
page sends: each Content-Security-Policy header, and each
<meta http-equiv="Content-Security-Policy"> in its head. A browser applies all of them, so each
has to allow fivebar. In each it checks the two things Getting started says a policy
has to allow:
- loading the script, by
script-src-elem, orscript-srcwithout it, ordefault-srcwithout either - sending what it counts, by
connect-src, ordefault-srcwithout it
If the page carries the fivebar tag, the tag is checked as written, nonce and all. Otherwise it’s the tag a
site’s settings give. A Content-Security-Policy-Report-Only header blocks nothing, so it’s checked
for what it would block once enforced.
It also checks the tag itself: that the page’s HTML has one, and that the site it counts for, its
data-domain or else the page’s own domain, is the page’s domain or one it’s under. fivebar refuses
what a page sends for any other site.
You can also check a site by its address, with its domain on the end:
https://fiveb.ar/docs/install/checker?domain=example.com.
What it cannot see
- Your other pages. Most sites send one policy everywhere, but a page can send its own. To check one, open it with your browser’s developer tools on the Console panel, which reports anything a policy blocks.
- A tag added by a tag manager, which isn’t in the page’s HTML.
- Whether the site a tag counts for is on fivebar, as a check needs no account. Its spelling should match the domain in the site’s settings.
- Content blockers and browser extensions, which can stop the script whatever the policy says.
The page is read by our bot, from Cloudflare’s network, so a site that turns bots away, or answers some places differently, may send it something other than what your visitors get. Nothing about a check is kept.