Skip to content
Back to skills

Blocked Links

ASecurity

Use when reviewing HTML source and JavaScript for links or resource URLs pointing to domains listed in common adblocker filter lists.

  • 74,358 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
developmentjavascriptgojavaapifrontendsecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add thedaviddias/Front-End-Checklist --skill blocked-links --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Blocked Links?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Blocked Links
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thedaviddias-blocked-links/badge)](https://www.skillsdirectory.com/skills/thedaviddias-blocked-links)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: blocked-links
description: "Use when reviewing HTML source and JavaScript for links or resource URLs pointing to domains listed in common adblocker filter lists."
metadata:
  category: security
  priority: low
  difficulty: intermediate
  estimatedTime: "15"
  source: frontendchecklist.io
  url: https://frontendchecklist.io/rules/security/blocked-links
---

# Blocked Tracking Links

When a navigation link's URL matches a tracking domain pattern, the adblocker may block the request entirely — the user clicks the link and nothing happens, breaking core site functionality.

## Quick Reference

- Adblockers block URLs matching domain-level filter lists like EasyList and EasyPrivacy
- Affected resources include external scripts, images, fonts, and API endpoints hosted on blocked domains
- Analytics and tag management scripts (Google Analytics, GTM, Hotjar, Heap) are commonly blocked
- Self-hosting or proxying external scripts through your own domain bypasses most domain-level blocks
- 20–40% of desktop users have an adblocker installed — blocked analytics skews your data significantly

## Check

Identify external script sources, image src URLs, iframe src URLs, and anchor href values that point to known tracking domains (googletagmanager.com, hotjar.com, facebook.net, doubleclick.net, etc.). Test whether these resources load successfully with uBlock Origin enabled.

## Fix

Self-host critical external scripts on your own domain. Use a reverse proxy or server-side route to forward requests to third-party analytics APIs. For navigation links, avoid using tracking redirect URLs — use direct destination URLs with UTM parameters appended instead.

## Explain

Explain how domain-level adblocker filter lists work, which domains are commonly blocked, how blocked resources affect site functionality and analytics accuracy, and the self-hosting approach to bypass domain blocks.

## Code Review

Review server config, headers, forms, and integration points related to Blocked Tracking Links. Flag exact responses, cookies, or browser behaviors that violate the rule, and verify them against the effective production-like response.

---

For full implementation details, code examples, and framework-specific guidance,
see `references/rule.md`.

Rule page: https://frontendchecklist.io/rules/security/blocked-links

Files in this skill

  • SKILL.md2.3 KB
  • references/rule.md4.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…