Analytics administration, dependency security, and public operations boundaries
The public analytics collection surface is separated from its protected administration surface; the website adds dependency gates, an anonymous funnel, canonical URLs, and operations checks.
Collection and administration no longer share a public entry point
The collection hostname continues to expose only the script and event endpoint. Administration uses a separate hostname with additional authentication and is not exposed to search engines.
Check security and observability before release
High-risk production dependency vulnerabilities, collector rate-limit logs, canonical URLs, and browser security headers are all covered by versioned checks instead of ad hoc server operations.
Changes in this update
- Two-layer authentication for the admin hostname
- Anonymous success-event funnel
- 429 and upstream error checks
- Canonical sitemap URLs
