generated: '2026-08-13' method: searched source: >- https://github.com/arp242/goatcounter (first-party repository), https://proxy.golang.org/zgo.at/goatcounter/v2/@latest, https://hub.docker.com/v2/repositories/arp242/goatcounter/, https://www.goatcounter.com/help/countjs-versions description: >- GoatCounter ships no conventional per-language API client SDK. The first-party distributions are the Go module / self-hosted server binary (which also carries the CLI), the official Docker image, and the browser tracking script count.js served from the provider's own CDN host gc.zgo.at. Every goatcounter package on npm is a third-party framework plugin (Docusaurus, Next.js, Gatsby, VuePress) authored by community maintainers, not by GoatCounter, so none is marked official. registries_checked: - registry: npm result: no first-party package (community framework plugins only) - registry: pypi result: 404 for goatcounter, goatcounter-api, py-goatcounter - registry: rubygems result: 404 for goatcounter - registry: crates.io result: no first-party crate - registry: pkg.go.dev / proxy.golang.org result: first-party module found packages: - language: go registry: go name: zgo.at/goatcounter/v2 url: https://pkg.go.dev/zgo.at/goatcounter/v2 install: go install zgo.at/goatcounter/v2/cmd/goatcounter@latest official: true version: v2.7.0 published: '2025-12-15' kind: server+cli note: >- The Go module is the GoatCounter application itself (self-hosted server plus the goatcounter CLI documented in cli/goatcounter-cli.yml), not an API client library. Version and date read from https://proxy.golang.org/zgo.at/goatcounter/v2/@latest. - language: n/a registry: docker name: arp242/goatcounter url: https://hub.docker.com/r/arp242/goatcounter install: docker pull arp242/goatcounter official: true version: v2.7.0 published: '2025-12-15' kind: container note: >- Official container image (Docker Hub description states "Official images"); last pushed 2025-12-15, matching the v2.7.0 GitHub release. Tag list is not enumerated here; version taken from the matching release. - language: javascript registry: cdn name: count.js url: https://gc.zgo.at/count.js install: '' official: true version: null published: null kind: browser-script note: >- Unpinned CDN distribution. The documented default src //gc.zgo.at/count.js floats to latest and carries no version in the URL and no registry metadata endpoint, so a consumer cannot tell which build they are served either — that is the finding, not a gap in this check. Pinned, SRI-verifiable builds are published alongside it (see the next entry). - language: javascript registry: cdn name: count.v5.js url: https://gc.zgo.at/count.v5.js install: '' official: true version: v5 published: '2025-06-09' kind: browser-script integrity: sha384-atnOLvQb9t+jTSipvd75X2yginT4PjVbqDdlJAmxMm+wYElFmeR6EmLP5bYeoRVQ note: >- Pinned, immutable build for subresource integrity. Version string and release date read verbatim from https://www.goatcounter.com/help/countjs-versions ("v5 (9 June 2025)"). Earlier pinned builds v4 (2023-12-08) and v3 (2021-12-01) remain served. - language: n/a registry: github-releases name: goatcounter (static binaries) url: https://github.com/arp242/goatcounter/releases install: download the statically compiled binary for your platform official: true version: v2.7.0 published: '2025-12-15' kind: binary note: Release date read from the GitHub releases API for arp242/goatcounter. third_party_seen: - registry: npm name: docusaurus-plugin-goatcounter version: 4.0.0 published: '2024-12-18' official: false - registry: npm name: next-goatcounter version: 1.0.6 published: '2024-11-24' official: false - registry: npm name: gatsby-plugin-goatcounter version: 0.4.0 published: '2020-08-10' official: false - registry: npm name: goatcounter-js version: 1.0.0 published: '2024-08-06' official: false note: Self-described as "An (unofficial) JavaScript library". maintainers: - FN: Kin Lane email: kin@apievangelist.com