generated: '2026-08-12' method: searched source: >- https://registry.npmjs.org/@mai-co/pixel (registry metadata) and https://data.jsdelivr.com/v1/packages/npm/@mai-co/pixel (CDN metadata) ownership: >- First-party. The npm scope @mai-co is maintained by zilong.wang@mai.co and lei.peng@mai.co, and the shipped bundle hardcodes MAI's own ingest host https://pixel.mai.co as its default apiEndpoint. package_count: 1 packages: - name: '@mai-co/pixel' language: javascript registry: npm official: true version: 1.0.5 published: '2026-05-07' first_published: '2026-04-18' release_count: 6 license: MIT url: https://www.npmjs.com/package/@mai-co/pixel registry_metadata: https://registry.npmjs.org/@mai-co/pixel description: >- MAI Pixel SDK — client-side event tracking and UTM attribution for Shopify Headless storefronts (Hydrogen, Next.js, Gatsby, Nuxt). Emits 11 commerce events to MAI's collection endpoint and carries first-party TypeScript declarations for every event payload. install: npm install @mai-co/pixel entrypoints: main: dist/mai-pixel.es.js module: dist/mai-pixel.es.js types: dist/index.d.ts module_type: esm typescript_types: true runtime_dependencies: [] build_toolchain: vite covers_api: MAI Pixel Event Collection API notes: - >- Ships complete TypeScript declarations (dist/*.d.ts) that document the full request envelope and every event parameter set — the closest thing MAI publishes to a machine-readable contract for the collection endpoint. - >- README is published in Chinese (README.md) with a Chinese-language variant (README.zh.md); both are integration guides rather than a reference for the HTTP endpoint itself. - 23 downloads in the 30 days ending 2026-08-09 (npm downloads API). - name: '@mai-co/pixel (jsDelivr build)' language: javascript registry: cdn official: true version: null published: null license: MIT url: https://cdn.jsdelivr.net/npm/@mai-co/pixel@1/dist/mai-pixel.min.js cdn_metadata: https://data.jsdelivr.com/v1/packages/npm/@mai-co/pixel description: >- Script-tag distribution of the MAI Pixel SDK, the install path MAI's own guide gives for non-Shopify-Liquid sites, GTM, and static storefronts. install: >- probed: url: https://cdn.jsdelivr.net/npm/@mai-co/pixel@1/dist/mai-pixel.min.js http_status: 200 bytes: 7067 fetched: '2026-08-12' notes: - >- version is null because the distribution URL MAI publishes is pinned only to the MAJOR version (`@1`), so it floats to the newest 1.x build. A site that pastes this tag cannot tell which build it is serving, and neither can we — that is the finding, not a gap in our check. The npm entry above records the concrete version the range currently resolves to (1.0.5). - >- Pinning the exact version in the documented snippet (`@mai-co/pixel@1.0.5`) would make the shipped bundle auditable by the merchant embedding it.