# How can I embed tracking JS into Discourse

**URL:** https://meta.discourse.org/t/how-can-i-embed-tracking-js-into-discourse/161129
**Category:** Data & reporting
**Created:** [17 augustus 2020 om 11:13 UTC](https://meta.discourse.org/t/how-can-i-embed-tracking-js-into-discourse/161129 "2020-08-17T11:13:58Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![jakubgs](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jakubgs/32/208790_2.png) [@jakubgs](https://meta.discourse.org/u/jakubgs)
#### Post date: [17 augustus 2020 om 11:22 UTC](https://meta.discourse.org/t/how-can-i-embed-tracking-js-into-discourse/161129/2 "2020-08-17T11:22:35Z")

</div>

Oh, and I should also add that I have seen this:

> [@Mitigate XSS Attacks with Content Security Policy](https://meta.discourse.org/t/mitigate-xss-attacks-with-content-security-policy/104243):
>
> bookmark This guide explains how to use Content Security Policy (CSP) to mitigate Cross-Site Scripting (XSS) attacks in Discourse. It covers CSP basics, configuration, and best practices. person_raising_hand Required user level: Administrator Summary Content Security Policy (CSP) is a crucial security feature in Discourse that helps protect against Cross-Site Scripting (XSS) and other injection attacks. This guide covers the basics of CSP, how it’s implemented in Discourse, and how to c…

And have added my Fathom domain to allows ones in the Content Security Policy allowed domains.

---

_[View the full topic](https://meta.discourse.org/t/how-can-i-embed-tracking-js-into-discourse/161129)._
