Cloudflare adds analytics script automatically when domains switch to its nameservers
Cloudflare’s default configuration has come under scrutiny after a user reported that the service automatically injected a JavaScript analytics snippet into a static website when the user switched the site’s nameservers to Cloudflare in order to enable R2 bucket serving via a custom subdomain. The issue was first documented in a comment thread on Hacker News, where the post garnered 46 points and four replies.
According to the user’s account, the injection occurred silently on a site that contained only HTML and no JavaScript, prompting the user to access Cloudflare’s Analytics dashboard, add the site to the analytics list, and then manually disable the snippet. The user described the practice as invasive, arguing that such features should require explicit opt‑in rather than an opt‑out process.
The incident highlights the importance of reviewing Cloudflare’s default settings after a nameserver change, particularly for sites that do not intend to run client‑side scripts. Administrators are advised to verify whether the analytics feature is enabled and to disable it if it is not needed, thereby avoiding unintended code insertion.