{"id":13725122,"url":"https://github.com/kremalicious/gatsby-plugin-matomo","last_synced_at":"2025-08-23T02:31:58.312Z","repository":{"id":32397090,"uuid":"132494885","full_name":"kremalicious/gatsby-plugin-matomo","owner":"kremalicious","description":"🥂 Gatsby plugin to add Matomo (formerly Piwik) onto a site.","archived":true,"fork":false,"pushed_at":"2024-12-20T14:53:35.000Z","size":11497,"stargazers_count":56,"open_issues_count":0,"forks_count":17,"subscribers_count":3,"default_branch":"main","last_synced_at":"2025-08-08T21:52:41.999Z","etag":null,"topics":["analytics","gatsby","gatsby-plugin","gatsbyjs","matomo","piwik"],"latest_commit_sha":null,"homepage":"https://kremalicious.com/gatsby-plugin-matomo","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kremalicious.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-05-07T17:33:29.000Z","updated_at":"2024-12-20T14:53:49.000Z","dependencies_parsed_at":"2023-12-25T18:04:30.140Z","dependency_job_id":"eff61e93-33d0-4089-947b-e7d753ea5786","html_url":"https://github.com/kremalicious/gatsby-plugin-matomo","commit_stats":{"total_commits":289,"total_committers":13,"mean_commits":22.23076923076923,"dds":"0.47750865051903113","last_synced_commit":"cdc4376e06653f530401e12b5c667f032b3cb0ca"},"previous_names":[],"tags_count":35,"template":false,"template_full_name":null,"purl":"pkg:github/kremalicious/gatsby-plugin-matomo","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kremalicious%2Fgatsby-plugin-matomo","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kremalicious%2Fgatsby-plugin-matomo/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kremalicious%2Fgatsby-plugin-matomo/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kremalicious%2Fgatsby-plugin-matomo/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kremalicious","download_url":"https://codeload.github.com/kremalicious/gatsby-plugin-matomo/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kremalicious%2Fgatsby-plugin-matomo/sbom","scorecard":{"id":569743,"data":{"date":"2025-08-11","repo":{"name":"github.com/kremalicious/gatsby-plugin-matomo","commit":"62e29c268196c95923854ddb1fedb8d76bb197b8"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4,"checks":[{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/21 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":0,"reason":"project is archived","details":["Warn: Repository is archived."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Pinned-Dependencies","score":5,"reason":"dependency not pinned by hash detected -- score normalized to 5","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/kremalicious/gatsby-plugin-matomo/codeql-analysis.yml/main?enable=pin","Info:   0 out of  10 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   1 third-party GitHubAction dependencies pinned","Info:   3 out of   3 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/ci.yml:46"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"SAST","score":7,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 0 commits out of 10 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"19 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-968p-4wvh-cqc8","Warn: Project is vulnerable to: GHSA-x4c5-c7rf-jjgv","Warn: Project is vulnerable to: GHSA-h5c3-5r3r-rr8q","Warn: Project is vulnerable to: GHSA-rmvr-2pp2-xj38","Warn: Project is vulnerable to: GHSA-xx4v-prfh-6cgc","Warn: Project is vulnerable to: GHSA-jr5f-v2jv-69x6","Warn: Project is vulnerable to: GHSA-xq7p-g2vc-g82p","Warn: Project is vulnerable to: GHSA-v6h2-p8h4-qcjw","Warn: Project is vulnerable to: GHSA-pxg6-pf52-xh8x","Warn: Project is vulnerable to: GHSA-fjxv-7rqg-78g4","Warn: Project is vulnerable to: GHSA-44fp-w29j-9vj5","Warn: Project is vulnerable to: GHSA-4pg4-qvpc-4q3h","Warn: Project is vulnerable to: GHSA-g5hg-p3ph-g8qg","Warn: Project is vulnerable to: GHSA-fjgf-rc76-4x9p","Warn: Project is vulnerable to: GHSA-76c9-3jph-rj3q","Warn: Project is vulnerable to: GHSA-rhx6-c78j-4q9w","Warn: Project is vulnerable to: GHSA-pq67-2wwv-3xjx","Warn: Project is vulnerable to: GHSA-8cj5-5rvv-wf4v","Warn: Project is vulnerable to: GHSA-52f5-9888-hmc6"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-20T15:58:55.224Z","repository_id":32397090,"created_at":"2025-08-20T15:58:55.225Z","updated_at":"2025-08-20T15:58:55.225Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271732383,"owners_count":24811312,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-23T02:00:09.327Z","response_time":69,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["analytics","gatsby","gatsby-plugin","gatsbyjs","matomo","piwik"],"created_at":"2024-08-03T01:02:13.617Z","updated_at":"2025-08-23T02:31:57.753Z","avatar_url":"https://github.com/kremalicious.png","language":"JavaScript","funding_links":[],"categories":["JavaScript"],"sub_categories":[],"readme":"[![gatsby-plugin-matomo](https://raw.githubusercontent.com/kremalicious/gatsby-plugin-matomo/main/src/gatsby-plugin-matomo.png)](https://kremalicious.com/gatsby-plugin-matomo/)\n\n# gatsby-plugin-matomo\n\n[![npm package](https://img.shields.io/npm/v/gatsby-plugin-matomo.svg)](https://www.npmjs.com/package/gatsby-plugin-matomo)\n[![Build Status](https://github.com/kremalicious/gatsby-plugin-matomo/workflows/CI%2FCD%20Pipeline/badge.svg)](https://github.com/kremalicious/gatsby-plugin-matomo/actions)\n[![Maintainability](https://api.codeclimate.com/v1/badges/067339a02f2058f5ba01/maintainability)](https://codeclimate.com/github/kremalicious/gatsby-plugin-matomo/maintainability)\n[![Test Coverage](https://api.codeclimate.com/v1/badges/067339a02f2058f5ba01/test_coverage)](https://codeclimate.com/github/kremalicious/gatsby-plugin-matomo/test_coverage)\n\n\u003e 🥂 Gatsby plugin to add Matomo (formerly Piwik) onto a site. https://kremalicious.com/gatsby-plugin-matomo/\n\n---\n\n**Deprecation notice: Gatsby has been abandoned (see [\"Is Gatsby discontinued?\"](https://github.com/gatsbyjs/gatsby/issues/38696) and [\"Is GatsbyJS Officially Dead?\"](https://github.com/gatsbyjs/gatsby/discussions/39062)) so this plugin is deprecated and won't receive any more updates.**\n\n---\n\n- [Features](#features)\n- [Usage](#usage)\n  - [Options](#options)\n- [Development](#development)\n- [Changelog](#changelog)\n- [License](#license)\n\n## Features\n\nPlugin uses sensible defaults prioritizing user experience, performance \u0026 privacy:\n\n- include tracking code in all server-side rendered routes\n- track all route views as custom events\n- load tracking scripts at end of `body` tag\n- use image tracking fallback for `noscript`\n- don't load anything when visitor has Do Not Track enabled\n- don't load anything in non-production environments\n- consent mode for privacy\n- allow loading tracking script locally\n- define paths to be excluded from tracking\n- `preconnect` to configured Matomo host url\n- dev mode for local development\n\n## Usage\n\n1. First, install the plugin from your project's root:\n\n   ```bash\n   cd yourproject/\n   npm i gatsby-plugin-matomo\n   ```\n\n2. Then load the plugin from your `gatsby-config.js` and set the required variables:\n\n   ```js\n   plugins: [\n     {\n       resolve: 'gatsby-plugin-matomo',\n       options: {\n         siteId: 'YOUR_SITE_ID',\n         matomoUrl: 'https://YOUR_MATOMO_URL.COM',\n         siteUrl: 'https://YOUR_LIVE_SITE_URL.COM'\n       }\n     }\n   ]\n   ```\n\n3. That's it!\n\n_NOTE: By default, this plugin only generates output when run in production mode. To test your tracking code, run `gatsby build \u0026\u0026 gatsby serve`, or set `dev` option to `true`_.\n\n### Options\n\n| Option                  | Explanation                                                                                                                                                                                                                                                                                                        |\n| ----------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |\n| `siteId`                | Your Matomo site ID configured in your Matomo installation.                                                                                                                                                                                                                                                        |\n| `matomoUrl`             | The url of your Matomo installation.                                                                                                                                                                                                                                                                               |\n| `siteUrl`               | The url of your site, usually the same as `siteMetadata.siteUrl`. Only used for generating the url for `noscript` image tracking fallback.                                                                                                                                                                         |\n| `matomoPhpScript`       | (optional) The name of your Matomo PHP script. Defaults to `matomo.php`                                                                                                                                                                                                                                             |\n| `matomoJsScript`        | (optional) The name of your Matomo JS script. Defaults to `matomo.js`                                                                                                                                                                                                                                               |\n| `exclude`               | (optional) Specify an array of pathnames where tracking code will be excluded. The pathname `/offline-plugin-app-shell-fallback/` is excluded by default.                                                                                                                                                          |\n| `requireConsent`        | (optional) If true, tracking will be disabled until you call `window._paq.push(['setConsentGiven']);`.                                                                                                                                                                                                             |\n| `requireCookieConsent`  | (optional) If true, no cookies will be stored or used until you call `window._paq.push(['setCookieConsentGiven']);`.                                                                                                                                                                                               |\n| `disableCookies`        | (optional) If true, no cookie will be used by Matomo.                                                                                                                                                                                                                                                              |\n| `cookieDomain`          | (optional) Specify cookie domain.                                                                                                                                                                                                                                                                                  |\n| `localScript`           | (optional) If set, load local `matomo.js` script from the given path, instead of loading it from your `matomoUrl`.                                                                                                                                                                                                  |\n| `trackLoad`             | (optional) If true, it will track the loading of the matomo library. Defaults to `true`.                                                                                                                                                                                                                           |\n| `respectDnt`            | (optional) If false, will load all scripts without respecting user preference to `Do Not Track` on browsers. Defaults to `true`.                                                                                                                                                                                   |\n| `dev`                   | (optional) Activate dev mode by setting to `true`. Will load all scripts despite not running in `production` environment. Ignores your local browser's DNT header too. Outputs some information in console about what it is doing. Useful for local testing but careful: all hits will be send like in production. |\n| `enableJSErrorTracking` | (optional) Enable basic JavaScript error tracking and reporting in Matomo by setting to `true`.                                                                                                                                                                                                                    |\n| `additionalTrackers`    | (optional) An array of additional trackers to track on different Matomo servers. Additional trackers are objects with the keys `siteId` and `trackerUrl` containing the full URL to the Matomo PHP script. Defaults to `[]`.                                                                                                                                                                                                                    |\n```js\nplugins: [\n  {\n    resolve: 'gatsby-plugin-matomo',\n    options: {\n      siteId: 'YOUR_SITE_ID',\n      matomoUrl: 'https://YOUR_MATOMO_URL.COM',\n      siteUrl: 'https://YOUR_LIVE_SITE_URL.COM',\n      // All the optional settings\n      matomoPhpScript: 'matomo.php',\n      matomoJsScript: 'matomo.js',\n      exclude: ['/offline-plugin-app-shell-fallback/'],\n      requireConsent: false,\n      requireCookieConsent: false,\n      disableCookies: false,\n      cookieDomain: '*.example.org',\n      localScript: '/matomo.js',\n      dev: false,\n      enableJSErrorTracking: true,\n      additionalTrackers: [\n        {\n          siteId: 'ADDITIONAL_SITE_ID',\n          trackerUrl: 'https://ADDITIONAL_MATOMO_URL.COM/matomo.php'\n        }\n      ]\n    }\n  }\n]\n```\n\n## Development\n\n```bash\nnpm i\nnpm start\n\n# create production build\nnpm run build\n\n# publishing to npm \u0026 GitHub releases\n# uses https://github.com/webpro/release-it\nnpm run release\nnpm run release minor\nnpm run release major\n```\n\n## Changelog\n\nSee [CHANGELOG.md](CHANGELOG.md).\n\n## License\n\nThe MIT License\n\nCopyright (c) 2024 Matthias Kretschmann\n\nPermission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the \"Software\"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.\n\n---\n\nMade with ♥ by [Matthias Kretschmann](https://matthiaskretschmann.com) ([@kremalicious](https://github.com/kremalicious))\n\nSay thanks with BTC:\n`35UUssHexVK48jbiSgTxa4QihEoCqrwCTG`\n\nSay thanks with ETH:\n`krema.eth`\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkremalicious%2Fgatsby-plugin-matomo","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkremalicious%2Fgatsby-plugin-matomo","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkremalicious%2Fgatsby-plugin-matomo/lists"}