CellWall Logo
Hubspot logo

Hubspot

AnalyticsAnalyticsOfficial Site

This script is part of HubSpot's analytics and marketing platform. When loaded on a website, it initializes the HubSpot tracking code, which collects data about user interactions. This includes page views, session duration, referral sources, engagement with content, and form submissions. The script places cookies in the user's browser to identify returning visitors, track their journey across multiple sessions, and link their activity to a contact record in HubSpot's CRM. It sends this collected data back to HubSpot's servers for processing and reporting, allowing website owners to gain insights into website performance, visitor behavior, and the effectiveness of their marketing campaigns. It enables features such as lead tracking, personalization of content, and segmentation of visitors based on their actions, all aimed at improving the user experience and optimizing marketing and sales efforts.

Capabilities

The HubSpot analytics script provides comprehensive visitor tracking capabilities, allowing website administrators to monitor key metrics like page views, bounce rate, and average session duration. It helps in understanding user engagement with different parts of the website, identifying popular content, and uncovering navigation patterns. Furthermore, it facilitates lead tracking by connecting anonymous visitor data with known contacts, providing a full view of a customer's journey from initial visit to conversion. This data is crucial for optimizing website content, improving user experience, and enhancing marketing campaign effectiveness.

  • Visitor Tracking
  • Page View Analysis
  • Session Tracking
  • Referral Source Identification
  • Form Submission Tracking
  • Lead Tracking
  • Marketing Automation Integration

Digital Footprint

Known Cookies

__hstc
Main visitor cookie for tracking a visitor's identity, domain, initial timestamp, last timestamp, current timestamp, and session number.2 years
hubspotutk
Tracks a visitor's identity across the website. Used when submitting forms to maintain visitor context.13 months
__hssc
Tracks sessions. Determines if a new session should be created for a visitor.30 minutes
__hssrc
Indicates if the user has restarted their browser. Set to 1 when a session is active and reloaded.session
_hstc
The main cookie for tracking visitors.13 months
_hssc
Tracks sessions.30 minutes
__hs_initial_opt_in
Determines if a visitor has accepted the cookie policy.7 days
messagesUtk
Stores a unique ID for chat visitors, allowing the chat widget to load past conversations and identify returning visitors.6 months
__hs_landing_page
Used to track the first page a visitor saw.6 months
__hs_last_visit
Used to track the last page a visitor saw.6 months
__hs_current_session
Identifies a current session. Used in conjunction with __hs_last_visit to determine new sessions.30 minutes
__hs_opt_out
Records the user's consent to cookies for the HubSpot service. If set, HubSpot will not place any other cookies.6 months
__cf_bm
Used by Cloudflare to provide security protection against bots and malicious traffic.30 minutes
hs-messages-is-open
Used to determine if the chat widget is open and minimize it if the user navigates away and then returns to the site.30 minutes
hs-messages-hide-welcome-message
Prevents the chat widget's welcome message from showing again for one day after it is dismissed.1 day

Endpoints

  • js-eu1.hs-analytics.net
  • track.hubspot.com
  • api.hubspot.com
  • forms.hubspot.com
  • static.hsappstatic.net
  • app.hubspot.com
  • api.hubapi.com

Security Incidents & Vulnerabilities

high4/18/2022

Cross-site Scripting vulnerability in HubSpot CMS with custom domain configuration.

high1/26/2023

Stored Cross-Site Scripting vulnerability in HubSpot.

high11/20/2023

Server-side request forgery (SSRF) vulnerability in HubSpot.