Open source
Read the code that runs on your visitors’ browsers
Everything that runs on your site or in your stack is open source under the MIT license: the tracker, SDKs and plugins. You shouldn’t have to take our privacy claims on trust.
| Project | What it is | License | Status |
|---|---|---|---|
Tracker (pa.js) | The browser script: pageviews, events, single-page apps, opt-out. Optional modules for outbound links and downloads, engagement and Web Vitals. | MIT | Available |
| Server SDKs | Node, Python, PHP, Go and Ruby clients for the server-side ingest API. | MIT | Planned |
| Framework packages | Next.js, Nuxt, React and more. | MIT | Planned |
| CMS plugins | WordPress, Ghost and others. | MIT (GPL where a platform requires it) | Planned |
| MCP server (local) | Connect AI agents to your analytics over the Model Context Protocol. | MIT | Planned |
| Terraform provider and CLI | Manage sites, goals and tokens as code. | MIT | Planned |
Verifiable builds
Each tracker release is versioned and published with a Subresource Integrity (SRI) hash, so you can pin the exact file you reviewed. The script identifies itself in a comment header. We don’t disguise it.
You can read the current tracker right now at /js/pa.js.
Contributing
Issues and pull requests are welcome. Please open an issue before large changes, keep the tracker dependency-free, and never add anything that stores data on the device or fingerprints it: those changes can’t be accepted.
Security issues go through our responsible disclosure process, not public issues.
Open-source projects can get free Pro for their own sites and docs, up to 1M events a month. Ask us.