# Installation checker

Type your site’s domain, and fivebar reads its home page and says whether the tag is there and the script can run.

A missing tag, a tag that names the wrong site, or a Content Security Policy that doesn’t allow fivebar stops it without a sign on the page: your pages work as ever, and nothing is counted. A check catches all three, before you launch or when a dashboard stays empty, and says what to change. It needs no account.

## What it checks

It asks for your site’s home page, following any redirects as a browser would, and reads every policy the page sends: each `Content-Security-Policy` header, and each `<meta http-equiv="Content-Security-Policy">` in its head. A browser applies all of them, so each has to allow fivebar. In each it checks the two things [Getting started](https://fiveb.ar/docs/install.md#content-security-policy) says a policy has to allow:

- loading the script, by `script-src-elem`, or `script-src` without it, or `default-src` without either
- sending what it counts, by `connect-src`, or `default-src` without it

If the page carries the fivebar tag, the tag is checked as written, nonce and all. Otherwise it’s the tag a site’s settings give. A `Content-Security-Policy-Report-Only` header blocks nothing, so it’s checked for what it would block once enforced.

It also checks the tag itself: that the page’s HTML has one, and that the site it counts for, its `data-domain` or else the page’s own domain, is the page’s domain or one it’s under. fivebar refuses what a page sends for any other site.

You can also check a site by its address, with its domain on the end: `https://fiveb.ar/docs/install/checker?domain=example.com`.

## What it cannot see

- Your other pages. Most sites send one policy everywhere, but a page can send its own. To check one, open it with your browser’s developer tools on the Console panel, which reports anything a policy blocks.
- A tag added by a tag manager, which isn’t in the page’s HTML.
- Whether the site a tag counts for is on fivebar, as a check needs no account. Its spelling should match the domain in the site’s settings.
- Content blockers and browser extensions, which can stop the script whatever the policy says.

The page is read by [our bot](https://fiveb.ar/docs/bot.md), from Cloudflare’s network, so a site that turns bots away, or answers some places differently, may send it something other than what your visitors get. Nothing about a check is kept.
