Pixellint 0.34.0 deepens collector protocols and payload validation.
Pixellint 0.34.0 adds two destination packs and deepens six existing packs. The new collectors are Cloudflare Web Analytics RUM and the published legacy Flashtalking FTrack transport. HubSpot browser pixels, Matomo bulk requests, Meta Conversions API, Pinterest Conversions API, TikTok Events API 2.0 and Amplitude Identify receive further request or payload checks. The engine now ships 161 vendor packs across 85 vendors.
This round focuses on observable contracts inside a request: the method that reached a collector, the actual encoding of a nested value, and the schema of every event or bulk item. Public vendor SDKs and server sources supply concrete protocol evidence where documentation has no complete wire table. A constraint seen in a producer remains advisory unless the source establishes a mandatory server requirement.
The evaluation separates 479 authored requirement cases from 122 model mutations. All 601 cases match their recorded expected outcomes in 0.34.0. A replay of 8,550 stored production artifacts adds one warning and zero errors. That small live delta is reported alongside the new coverage because the snapshot contains no complete HTTP captures. Most transport and multipart additions cannot appear in that stored corpus.
Cloudflare RUM gets a collector contract separate from its loader.
The new RUM pack recognizes the exact /cdn-cgi/rum routes used by automatic customer domains and the manual collector. Cloudflare documents POST ingestion and OPTIONS preflight. Invalid methods receive a contract error; preflight does not require metric fields.
Load and WebVitals fields come from the inspected official beacon and receive producer warnings. Synthetic browser execution captures a real SDK-emitted Load payload without sending it to the collector. The existing beacon loader remains a separate pack.
Configured forwarding URLs and account acceptance remain outside these local checks. The release preserves that distinction rather than inferring ownership or configured domain access from a payload.
Legacy FTrack encoding is checked without claiming private collectors.
The FTrack pack covers d9.flashtalking.com/lgc and the device object emitted by the published d9core SDK. Its form transport contains JSON wrapped in two encodeURIComponent layers. After form decoding, one inner percent layer remains. That layer needs strict UTF-8 and percent handling while keeping a literal plus intact. Treating it as another form query would change a valid value before the field checks run.
Native field types, plugin array elements and fixed empty containers follow the inspected producer. The implementation preserves null alternatives observed in browser branches and keeps unknown additional fields open. Desktop and mobile producer executions provide controls alongside positive and negative authored cases. All destination findings for this source scope remain warnings because the SDK is not a published backend rejection specification.
This addition does not validate the current /img D9c/D9v transport or private ft.stat events. Their tuple constructors were not established by the accessible sources. Browser fingerprint parity also remains incomplete. The new pack names the legacy surface it can check and retains the uncovered collectors in the audit.
HubSpot browser pixels now follow the official SDK inventory.
The existing HubSpot pixel pack expands beyond __ptq.gif to the source-proven __ptbe.gif and __ptc.gif branches. Its inventory now covers common SDK fields, identity serialization, consent masks and known event contexts. The official producer supports warnings for these values; the earlier ecosystem-only treatment of Hub ID presence is corrected to reflect that stronger source and the absence of a public backend mandate.
Identity values contain another query representation. The new decoder preserves Unicode, literal property names and repeated values. Form-style plus handling belongs to this representation, whereas the FTrack inner layer preserves plus. Those two encodings have different semantics even when both travel inside an outer request query or form body. Their authored boundary cases make the distinction visible.
Complete HTTP captures can also check the image GET transport and repeated tracking-cookie bound. Bare URLs still lack that repeated-value bound in the current implementation. Contact state, configured event ownership, custom tracking domains and the full canonical email validator remain explicit limits. Unknown future event labels and extra custom properties are accepted rather than converted into speculative errors.
Matomo bulk maps reuse the readers defined by its server source.
Matomo bulk requests can carry query strings or native parameter maps. This release applies the event checks to the map representation using the behavior found in pinned Matomo server source and documented PHP 8 conversions. Nested arrays and original scalar types matter because different server readers interpret them differently. Converting every field into a generic JSON string would lose that behavior.
The source review also corrects older assumptions about ignored boolean entries, associative request containers and a numeric outer token. Native entries no longer skip the relevant event dependencies simply because they are objects. Positive and negative cases include later bulk items so the first well-formed event cannot hide a failure elsewhere in the batch.
No PHP backend was executed locally. Compatibility is scoped to the inspected readers, their upstream test evidence and the declared PHP behavior. Chronological advice compares explicit parseable cdt timestamps and warns on a backward step; missing timestamps acquire no inferred clock. Custom readers, prior session history and account configuration remain outside that bounded check. Exact matomo.php and piwik.php routes remain recognized on Matomo Cloud and self-hosted domains.
Conversion APIs gain transport depth and source-specific payload checks.
Meta captures now recognize credential alternatives established by official SDKs while preserving the distinction between transport representations. Form data supports object events and SDK-produced JSON strings; decoded events receive the existing event contracts. App, attribution, commerce and messaging model fields add typed advisory checks. A website event missing its expected user agent receives a warning rather than a hard rejection.
Pinterest gains operation-level checks from the current official OpenAPI source: POST, JSON content type, bearer authentication and an object request body. The model review found the existing body inventory already mapped the current published field and bound set, so this work adds request context without claiming that a higher rule count was needed for every destination.
TikTok Events API 2.0 now checks batch containers and later items, with web, app and CRM context governing the relevant fields. Page URL advice applies to web events; app and lead branches retain their own requirements. Official template transport and producer model expectations remain distinguished from hard published limits. The three conversion packs contribute 117 new source-based cases, including 14 separately labeled primary-model type mutations.
Multipart Identify fields become observable within declared limits.
Amplitude documents multipart Identify requests. The engine can now decode bounded UTF-8 text fields and reuse the existing identification rules. It preserves field names, order, duplicates, Unicode and literal plus or percent characters. Query and path authority remain intact when a form contains similarly named values, so a body field cannot silently replace the endpoint context.
Multipart boundaries, disposition names and supported charset declarations are checked before assuming the engine has seen a field. File parts, alternate charsets, ambiguous headers, transfer encoding, oversized captures and compressed binary bodies remain informative. Missing-value errors are suppressed when the representation prevents observation. The capture model carries text and cannot recover original binary octets.
The 31 authored multipart cases cover successful decoding, malformed framing, duplicate handling and unsupported representations. The decoder remains bounded to 4 MiB,1,024 parts and 16 KiB headers. These are engine observation limits, not invented Amplitude service limits. Project permissions, throttling and identity history still require remote or session context.
The stored replay adds one warning and preserves every vendor selection.
The frozen D 1 snapshot contains 8,397 VAST artifacts,108 URLs and 45 JSON artifacts. Both engines select destination packs for 4,398 stored artifacts. Another 2,554 receive core checks and 1,598 receive vendor identification without a destination pack. No artifact gains or loses vendor selection in this round. Directory identification remains excluded from the protocol coverage count.
Error findings remain 284 and error-bearing artifacts remain 216. Warning findings rise from 727 to 728. The added diagnostic concerns a website event without the user agent expected by the Meta SDK collection example. It is advisory and source-supported. The replay contains no complete HTTP captures, so it cannot demonstrate the new collector methods, transport headers or multipart handling against captured HTTP traffic.
The public report exposes aggregate counts, clocks and evaluation methods. It contains no stored artifacts, sample identifiers, credentials or customer URLs. The per-pack audit keeps source accessibility and residual requirements visible, including RTB House impression collectors and Flashtalking private ad-events that still lack adequate wire evidence. No destination is certified complete by this release.
Sources
- Pixellint 0.34.0 release and native downloads
- Per-pack sources, exact evidence hashes and remaining requirements
- HTTP capture schema and multipart representation limits
- Aggregate 0.33.0 to 0.34.0 replay and evaluation report
- Cloudflare collector methods and automatic/manual endpoints
- Published Flashtalking legacy FTrack producer
- Hash-pinned HubSpot SDK execution proof
- Matomo single and bulk Tracking API
- Amplitude Identify multipart examples
- Multipart form-data representation requirements
Contract pages
The dated argument is above. These pages are the field lists.