Pinning the tracking script (Subresource Integrity)
For strict security policies: make the browser refuse the tag if its code changes.
2 min readFor Developers
Setup → Install & domains shows an optional pinned snippet with an integrity hash and crossorigin="anonymous". The browser compares the downloaded ex.js with the hash and refuses to run it if a single byte differs.
<script async src="https://YOUR-ELEXY-DOMAIN/ex.js" integrity="sha384-…" crossorigin="anonymous" data-site="EX-XXXXXXXXXX"></script>
Good to know: Every tracker release changes the hash. A pinned tag stops collecting until you paste the new snippet, so use it only where your security policy requires it, and check the Install page after each release notice.