Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Marketing site loads its analytics script over http, so browsers block it and no visits are recorded

Open Beginner friendly
#1,777 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
1/5
Estimated time
Under an hour
Newbie friendliness
94/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript
Domain
frontend

Research direction

In apps/outreach/src/components/layout/Head.astro, the analytics script URL is explicitly identified. Change its scheme to HTTPS, then run the apps/outreach build and inspect dist/en/index.html to confirm it references the HTTPS URL; the issue notes there is no unit or Playwright suite.

Written by the indexing model from the issue text.

Description

Area: Outreach Bug Difficulty: Low Good First Issue Priority: Medium

The analytics script on the marketing site is requested over plain http://, so browsers block it as mixed content and the site records no visits. opendatacapture.org is served only over HTTPS (http:// redirects to https://). Browsers refuse to load an active script from an http:// URL on an HTTPS page, and they do not upgrade script requests automatically. The analytics host itself serves the same file over HTTPS: https://analytics.douglasneuroinformatics.ca/js/script.js returns 200. The URL has been http:// since tracking was added in 2023, so marketing-page analytics have likely never worked in production.

Where

apps/outreach/src/components/layout/Head.astro:44-45:

<!-- prettier-ignore -->
<script is:inline defer data-domain="opendatacapture.org" src="http://analytics.douglasneuroinformatics.ca/js/script.js"></script>

Reproduce

  1. Open https://opendatacapture.org/en/ in Chrome with the devtools open.
  2. Look at the Console and Network panels, or run typeof window.plausible in the console.

Actual: Chrome reports the http://analytics.douglasneuroinformatics.ca/js/script.js request as blocked mixed content. Its resource timing entry has status 0 and 0 bytes transferred, and window.plausible is undefined, so the script never ran.
Expected: the script loads over HTTPS and page views are recorded.

Tests

apps/outreach has no unit or Playwright suite, by decision (apps/outreach/AGENTS.md). Verify through the build: dist/en/index.html references https://analytics.douglasneuroinformatics.ca/js/script.js.

Suggested fix

Change the src to https://analytics.douglasneuroinformatics.ca/js/script.js.

Dominant language
TypeScript
Stars
119
Forks
19
Avg merge
1d 2h
Merged PRs (30d)
56

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from DouglasNeuroInformatics/OpenDataCapture

All issues in DouglasNeuroInformatics/OpenDataCapture

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.